
In an aggressive move to counter one of the most expansive botnet operations currently active, Google is taking legal action against a massive malware campaign known as BadBox 2.0. This malware, which has been detected on more than 10 million Android-powered devices—mostly cheap and unofficial streaming TV boxes—has transformed these set-top boxes into a sprawling network of malicious bots. While the devices are typically marketed in shady corners of the web or through unauthorized resellers as a way to “stream everything for free,” their real purpose appears far more sinister.
According to a detailed report from BleepingComputer, the malware is not only enabling a large-scale advertising fraud operation—stealing ad revenue from companies like Google itself—but also facilitating criminal schemes ranging from DDoS attacks to proxy sales and ransomware distribution. The botnet enables hackers to spoof legitimate advertising activity and redirect funds away from the intended platforms. These fake apps and fraud tools, distributed primarily through unregulated app stores, are capable of reaching Android phones worldwide, and the revenue from these schemes is believed to flow back to operators based in China.
Google claims that these compromised devices are being used to run unauthorized proxy networks, which are then sold to other cybercriminals for steep prices—up to $1,390 for 500GB of proxy access. To dismantle the infrastructure supporting this fraud ring, Google is taking a rare step: invoking the Racketeer Influenced and Corrupt Organizations Act (RICO), typically used by U.S. authorities to prosecute organized crime. The tech giant is asking a U.S. District Court to authorize the takedown of over 100 domains linked to the malware’s backend operations.
This legal push not only targets the malware operators themselves but also seeks to force major hosting and domain service providers—such as GoDaddy, Cloudflare, Amazon, and Alibaba—to shut off access to the malicious sites. If the injunction is granted, these companies would be compelled to sever ties with the infected infrastructure, potentially crippling the botnet’s operations.
While the affected devices run versions of Android, they are not certified by Google and lack the official Play Store or its associated security layers. These boxes are particularly vulnerable due to Android’s open-source nature, which allows bad actors to modify the OS and pre-load malware before the device even reaches a customer. Google has already attempted to mitigate the problem through its ad platforms and by shutting down fake accounts, but with the infection continuing to spread, the company now appears to be escalating the matter to the courts as a last resort.
In addition to seeking domain shutdowns, Google is also asking for financial relief in the form of damages, legal fees, and injunctions to prevent similar malware campaigns from rising up under new names. If successful, this legal case could serve as a precedent for cracking down on the murky gray market of infected Android devices and the advertising fraud economy that feeds off of them.




