CyberzSOC

Publication detail
← Back to advisories & guidance

Home Internet Connected Devices Facilitate Criminal Activity ↗ source

June 5, 2025 FBI Alert

Summary

Share on X X.com Share on Facebook Facebook Email Email The Federal Bureau of Investigation (FBI) is issuing this Public Service Announcement to warn the public about cyber criminals exploiting Internet of Things (IoT) 1 devices connected to home networks to conduct criminal activity using the BADBOX 2.0 botnet 2 . Cyber criminals gain unauthorized access to home networks through compromised IoT devices, such as TV streaming devices, digital projectors, aftermarket vehicle infotainment systems, digital picture frames and other products. Cyber criminals gain unauthorized access to home networks by either configuring the product with malicious software prior to the users purchase or infecting the device as it downloads required applications that contain backdoors, usually during the set-up process. 3 Once these compromised IoT devices are connected to home networks, the infected devices are susceptible to becoming part of the BADBOX 2.0 botnet and residential proxy services 4 known to be used for malicious activity. BADBOX 2.0 was discovered after the original BADBOX campaign was disrupted in 2024. BADBOX was identified in 2023 and primarily consisted of Android operating system devices that were compromised with backdoor malware prior to purchase. BADBOX 2.

News Coverage

No coverage found in monitored research blogs or news feeds.

CVEs Referenced in This Publication

No CVEs are referenced in this publication.

Vendors Named in This Publication

Each vendor links to its Known Exploited Vulnerabilities catalog page. Only vendors that appear in the KEV catalog are listed, either because the publication cites one of their KEV entries or because it names them directly.