Badbox Brings Drive By Malware to New Level in New Version
By: Jim Stickley and Tina Davis
May 10, 2025
There’s a new twist on an earlier version of Badbox that’s infecting Android devices with its malware. Badbox 2.0 has arrived and it’s infecting everything from TV streaming devices used at home and in schools and businesses, to car infotainment systems. Badbox 2.0 is blowing up with help from drive-by downloads and victims who have no idea they just unleashed a “Badbox bomb.”

Security researchers say Badbox 2.0 signals a key change in tactics now focusing on traditional drive-by downloads. They also say a single bad actor isn’t behind this adware, but rather a China-based ecosystem of bad actors. The many interconnected members spread Badbox 2.0’s malicious pop-ups and click bait adware, all with the help of victims as proxies for their cybercrimes.
How Bad Boy Badbox 2.0 Works
Using common infection techniques helps this sneaky Bad Boy spread. By focusing on malware-infected software rather than infecting low-level firmware, Badbox 2.0 is thriving. The way this malware dupe’s users into downloading it is as varied as the many members of its network.

In one typical scheme, bad actors create an everyday, non-threatening app that passes Google Play Store’s malware scanning. A future victim shopping in a third-party store sees the app passed the vetting and assumes it’s safe to download. What they don’t know is the app is a duplicate filled with Badbox 2.0’s adware, and they might never know they were involved in a drive-by download.
Secure Tips
No matter what tricks Badbox 2.0’s bad actors use to draw victims into their web, there’s a few basic steps we can all take to avoid downloading malware. Sideloading third-party apps is very risky since these stores don’t inspect for malware and you’re rolling the dice using them. Although not perfect, download from official app stores since they scan all apps for malware before posting them. If you use anti-virus software, and you definitely should, keep it updated with the latest bug fixes and security patches.
Although it seems to be tougher staying safe online these days, don’t panic, that’s what hackers want us to do. Using a good dose of common sense and cyber-smarts helps everyone stay above malware like Badbox 2.0.
