What the FBI said
The FBI’s public service announcement (June 2025, linked at the end of this page) described the BADBOX 2.0 botnet:
- More than a million off-brand internet-connected devices were infected, including TV streaming devices, digital projectors, car infotainment systems and digital picture frames.
- Most affected devices were made in China, and some were infected before they were sold, while others picked up malware from apps with hidden backdoors.
- The FBI advised people to watch for devices that ask you to disable Google Play Protect, and generic TV streaming devices advertised as unlocked or able to access free content.
Infected devices can be used to route criminals’ internet traffic through your home connection.
Check your box
- Is it Play Protect certified? Open the Google Play Store app, go to its settings, then About, and look for Play Protect certification. It should say the device is certified. If Google Play is missing altogether, the box isn’t certified.
- Did the seller or instructions tell you to turn off Play Protect? That’s one of the FBI’s named warning signs.
- Did it come preloaded with unfamiliar app stores or apps offering free channels and films? Those are both a legal risk and a common malware route.
- Does your router show heavy traffic from the box when you’re not using it? Many routers list per-device traffic in their app.
If you’re worried
- Disconnect it from your network.
- Don’t rely on a factory reset if the box was sold with malware built in.
- Replace it with a certified device from a known brand. See how to choose an Android TV box.
- Change passwords you’ve used on the box, such as your streaming accounts.
Staying safe with IPTV
A player app should ask for your own subscription, and it shouldn’t need you to weaken your device’s security. See is IPTV safe? and IPTV scams for the bigger picture.
