Technology
FBI warns over 1 million Android devices hijacked by malware
NEWYou can now listen to Fox News articles!
Everything that connects to the internet can be hacked by malware.
This includes your phones (both Android and iPhones) and laptops (whether Windows, Mac or even lesser-known systems like Linux). Devices like your Wi-Fi router and security cameras aren’t safe either.
But who would have thought hackers are now targeting your smart TVs, streaming boxes, projectors and tablets, too? That’s right, the FBI warns that bad actors have hijacked over a million of these devices with malware, turning them into unwitting participants in a global cybercrime network.
Sign up for my FREE CyberGuy Report
Get my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox. Plus, you’ll get instant access to my Ultimate Scam Survival Guide — free when you join.
Remote control and smart TV (Kurt “CyberGuy” Knutsson)
FBI warns: Over 1 million smart devices infected with BadBox 2.0 malware
The FBI is warning that more than a million smart TVs, streaming boxes, projectors and tablets have been infected by a massive malware operation called BadBox 2.0. The malware turns home electronics into participants in a global network of cybercrime, often before the user even powers them on.
In a statement, the FBI says BadBox 2.0 is commonly found on cheap Android-based devices manufactured in mainland China. These include uncertified tablets, connected TV boxes and other Internet of Things hardware. Many of the infected devices ship with the malware preinstalled. Others are compromised during setup, often through malicious firmware updates or sideloaded apps from unofficial marketplaces.
FBI WARNS OF HACKERS EXPLOITING OUTDATED ROUTERS. CHECK YOURS NOW
Once infected, the devices connect to a command and control server, allowing hackers to reroute malicious traffic through home networks, load fraudulent ads in the background and carry out credential-stuffing attacks without the user knowing. Essentially, your smart TV could be quietly helping someone break into other people’s accounts.
The botnet is primarily used to turn infected devices into residential proxy nodes, providing hackers with anonymous access to real home IP addresses. That means your TV or projector might unknowingly be helping cybercriminals bypass security systems, commit ad fraud or brute-force online accounts while hiding behind your internet connection.
A person holding a tablet (Kurt “CyberGuy” Knutsson)
DON’T CLICK THAT LINK! HOW TO SPOT AND PREVENT PHISHING ATTACKS IN YOUR INBOX
Badbox malware history: From TV boxes to over 1 million infected devices
BadBox first appeared in 2023 on generic TV boxes, such as the T95. The original botnet was briefly disrupted in Germany in 2024 when security researchers “sinkholed” the malware’s command servers. That wiped out part of the operation, but not for long. Just a week later, the malware reappeared on nearly 200,000 devices, including more recognizable brands like Hisense smartphones and Yandex TVs.
By March 2025, BadBox had evolved into BadBox 2.0, with more than 1 million active infections detected by HUMAN’s Satori Threat Intelligence team. The majority of devices are uncertified Android Open Source Project builds. These are not official Android TV OS products and are not protected by Google Play Protect.
Researchers say the malware has been spotted in 222 countries. A significant number of infections are concentrated in Brazil, followed by the United States, Mexico and Argentina.
The FBI, working with Google, Trend Micro, HUMAN and the Shadowserver Foundation, recently disrupted communications between more than 500,000 infected devices and their control servers. However, the botnet continues to grow as more compromised products reach consumers and remain unnoticed.
Symptoms of infection include strange app marketplaces, disabled Play Protect settings or devices advertised as being unlocked or capable of free streaming. Many of these products come from unknown brands and are sold through unofficial sellers. If you have recently purchased a budget Android TV box or projector, especially one that is not certified by Google, you may want to take a closer look.
Smart TV (Kurt “CyberGuy” Knutsson)
ANDROID SCAM LETS HACKERS USE YOUR CREDIT CARD REMOTELY
How to tell if your device might be infected with BadBox 2.0
If you’re wondering whether your smart TV, streaming box, projector or tablet could be part of the BadBox 2.0 botnet, here are some warning signs and checks you can do.
1. You bought a low-cost Android-based device from an unknown or no-name brand: Devices sold online through third-party sellers or unknown brands, especially if advertised as “unlocked,” “jailbroken” or offering free streaming, are at higher risk. Models like the T95 box or other generic Android TV boxes are known carriers. Specifically, the following devices have been identified as impacted by BadBox malware:
Device model: TV98, X96Q_Max_P, Q96L2, X96Q2, X96mini, S168, ums512_1h10_Natv, X96_S400, X96mini_RP, TX3mini, HY-001, MX10PRO, X96mini_Plus1, LongTV_GN7501E, Xtv77, NETBOX_B68, X96Q_PR01, AV-M9, ADT-3, OCBN, X96MATE_PLUS, KM1, X96Q_PRO, Projector_T6P, X96QPRO-TM, sp7731e_1h10_native, M8SPROW, TV008, X96Mini_5G, Q96MAX, Orbsmart_TR43, Z6, TVBOX, Smart, KM9PRO, A15, Transpeed, KM7, iSinbox, I96, SMART_TV, Fujicom-SmartTV, MXQ9PRO, MBOX, X96Q, isinbox, Mbox, R11, GameBox, KM6, X96Max_Plus2, TV007, Q9 Stick, SP7731E, H6, X88, X98K, TXCZ
2. Your device is not Google-certified: If your Android device doesn’t support Google Play Protect or doesn’t show the Play Protect certification in the Play Store settings, it’s likely running on an uncertified version of Android. That’s a major red flag. To check:
- Open the Google Play Store.
- Tap your profile icon > Settings > About.
- Look for Play Protect certification. If it says “Device is not certified,” that’s a problem.
3. Suspicious behavior or strange apps: Look for unfamiliar apps you didn’t install, apps labeled with foreign characters or alternative app stores on your device. BadBox-infected devices often come with shady apps preloaded.
4. Google Play Protect is disabled: If Play Protect has been turned off without your knowledge or is missing altogether, your device may be vulnerable to compromise.
5. Your home internet is acting strange: If your network is unusually slow or your router shows unknown devices connected, one of your smart devices may be hijacked and rerouting traffic as part of a residential proxy network.
6. The device came with outdated or unofficial firmware: If your device doesn’t receive software updates or has a strange update process, that’s another potential sign it’s not legit or may be compromised.
FBI WARNS OF SCAM TARGETING VICTIMS WITH FAKE HOSPITALS AND POLICE
8 ways to protect your devices from BadBox 2.0 and Android malware
Want to stay safe? Here are eight practical steps you can take to protect your smart devices from BadBox 2.0 malware and other hidden Android threats.
1. Use strong antivirus software: Protecting your devices starts with powerful antivirus protection. Malware like BadBox 2.0 often comes preinstalled on cheap, uncertified Android devices, infecting them before you even power them on. A trusted antivirus app can help detect hidden threats, block malicious traffic and warn you about suspicious behavior that might otherwise go unnoticed. Get my picks for the best 2025 antivirus protection winners for your Windows, Mac, Android and iOS devices.
2. Only buy certified and trusted devices: Stick to devices certified by Google or other recognized platforms. Avoid generic or off-brand Android boxes, tablets and projectors, especially if they are advertised as unlocked or include free streaming. Cheap, uncertified devices are more likely to come with malware preinstalled.
3. Avoid sideloading apps from unofficial sources: Do not install apps from third-party app stores or download APK files from unknown websites. These files can contain hidden malware. Use only official app stores like the Google Play Store that scan apps for threats.
4. Check your device settings for tampering: Look for signs like Google Play Protect being turned off, the presence of unfamiliar app stores or suspicious apps running in the background. These are possible signs your device is compromised.
5. Monitor your network for unusual activity: If your internet slows down suddenly, or you notice unknown devices on your Wi-Fi, investigate. Use your router’s settings or a network monitoring app to track strange behavior or unauthorized connections.
6. Disconnect and replace suspicious hardware: If a device is behaving oddly or was purchased from an untrusted source, unplug it from your network. Consider replacing it with a product from a reputable brand and a verified seller.
7. Keep your devices and apps updated: Install system and app updates regularly. Even though cheap devices may not always offer updates, keeping your software current reduces your risk. Choose brands that are known for providing reliable security patches.
8. Secure your router and home network: Your devices are only as safe as the network they’re connected to. Set a strong, unique password for your Wi-Fi router and update its firmware regularly. Disable remote access unless absolutely necessary and use WPA3 encryption if available. Consider using a password manager to generate and store complex passwords. Get more details about my best expert-reviewed password managers of 2025 here.
As BadBox 2.0 continues to evolve, protecting your entire home network, not just individual devices, has become essential to staying one step ahead of cybercriminals.
THIS IS WHAT YOU ARE DOING WRONG WHEN SCAMMERS CALL
Kurt’s key takeaway
It’s alarming how something as simple as a budget streaming box or projector could be quietly working for cybercriminals. As smart devices become part of almost everything we do, being a careful and informed consumer matters more than ever. Small steps like buying from trusted brands and avoiding unofficial downloads can make a big difference in keeping your home and personal data safe.
With over a million devices infected, who should be held accountable: manufacturers, governments or consumers? Let us know by writing us at Cyberguy.com/Contact.
For more of my tech tips and security alerts, subscribe to my free CyberGuy Report Newsletter by heading to Cyberguy.com/Newsletter.
Ask Kurt a question or let us know what stories you’d like us to cover.
Follow Kurt on his social channels:
Answers to the most-asked CyberGuy questions:
New from Kurt:
Copyright 2025 CyberGuy.com. All rights reserved.
Technology
Rad Power Bikes files for bankruptcy protection
Rad Power Bikes, the once dominant electric bicycle brand in the US, filed for Chapter 11 bankruptcy protection this week as it seeks to sell of its company. The move comes less than a month after Rad Power said it could not afford to recall its older e-bike batteries that had been designated a fire risk by the US Consumer Protection Safety Commission.
The bankruptcy, which was first reported by Bicycle Retailer, was filed in US Bankruptcy Court for the Eastern District of Washington, near the company’s headquarters in Seattle. Rad Power lists its estimated assets at $32.1 million and estimated liabilities at $72.8 million. Its inventory of e-bikes, spare parts, and accessories is listged at $14.2 million, Bicycle Retailer says.
It’s a stunning reversal for the once leading e-bike company in the US. Mike Radenbaugh founded the company in 2015 after several years of selling custom-made e-bikes to customers on the West Coast. Rad Power quickly grew to over 11 distinct models, including the fat-tire RadRover, the long-tail RadWagon, and the versatile RadRunner. Rad Power Bikes raised an approximate total of $329 million across several funding rounds, primarily in 2021, with major investments from firms like Fidelity, Morgan Stanley, and T. Rowe Price.
But in the wake of the post-covid bike boom, things started to go south. There were supply chain disruptions, safety recalls, several rounds of layoffs, and executive turnover. Last month, Rad Power said it was facing “significant financial challenges” that could lead to its imminent closure without a cash infusion.
The CPSC warning apparently was the nail in the coffin. The company’s older batteries could “unexpectedly ignite and explode,” the agency warned, citing 31 fires, including 12 reports of property damage totaling $734,500. There weren’t any injuries, but the company said it couldn’t afford a costly recall.
Rad Power could still live on if its able to find a buyer for its assets and brand. Dutch e-bike make VanMoof was able to find a buyer following its 2023 bankruptcy. And Belgium’s Cowboy is in talks to be acquired by a French holding company of several bike brands. Rad Power will continue to operate as it restructures its debts under court supervision, and in a statement to Bicycle Retailer said it will continue to sell bikes and work with customers and vendors as it moves forward with the process.
Technology
Chrome rolls out AI podcast feature on Android
NEWYou can now listen to Fox News articles!
Chrome on Android now offers a fresh way to digest information when your hands are busy or your eyes need a break.
A new update powered by Google Gemini can turn written webpages into short podcast-style summaries. Two virtual hosts chat about the content, making it feel easier to follow during your commute or while you multitask.
This upgrade builds on Chrome’s long-standing read-aloud tool, yet now adds a more natural and lively delivery. It does not work on every website, so some pages will still use the original word-for-word reading. When the AI option appears, though, the audio feels polished and smooth.
Below is how to try it on your Android phone right now.
Sign up for my FREE CyberGuy Report
Get my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox. Plus, you’ll get instant access to my Ultimate Scam Survival Guide — free when you join my CYBERGUY.COM newsletter.
HOW TO DISABLE GEMINI AI ON ANDROID AND KEEP CONTROL OF YOUR APPS
Make sure you have the newest Chrome version so the AI podcast feature works. (Cyberguy.com)
Update Chrome before you start
First, make sure Chrome is current in the Play Store by opening the Play Store, searching for Google Chrome and tapping Update if it appears. The AI podcast feature works with version 140.0.7339.124 or newer, so confirm you have at least that version installed. Once you finish the update, open Chrome and pick any webpage with text you want to hear.
Settings may vary depending on your Android phone’s manufacturer.
Open the More menu
- Tap the More icon or the three vertical dots in the upper right corner. This reveals a set of options that control how Chrome displays or reads the page.
Select Listen to this page
- Choose Listen to this page. You will see a small Generating AI playback banner at the bottom. The processing is fast, so you will not wait long.
Hear the AI hosts discuss the page
- Chrome will start a mini podcast with two voices talking through the content. You can tap the playback bar to pause, rewind or jump ahead. The panel stays on screen and follows you as you scroll.
Switch to standard playback when you want
- The AI audio keeps going even if you leave the webpage. If you prefer a traditional word-for-word readback, tap the AI playback icon in the lower left and pick Standard Playback.
Chrome begins creating the AI audio as soon as you tap the “Listen to this Page” option. (iStock)
ANDROID EMERGENCY LIVE VIDEO GIVES 911 EYES ON THE SCENE
What this means to you
This feature can make long articles easier to absorb when you are on the move. You get a quick, conversational rundown without having to read a full page. It also helps you revisit information faster since the controls work like any audio player. If you enjoy podcasts, this tool gives you a familiar way to stay informed without draining your attention.
Take my quiz: How safe is your online security?
Think your devices and data are truly protected? Take this quick quiz to see where your digital habits stand. From passwords to Wi-Fi settings, you’ll get a personalized breakdown of what you’re doing right and what needs improvement. Take my Quiz here: Cyberguy.com.
Kurt’s key takeaways
Chrome’s AI podcast feature brings a new layer of convenience to Android. It saves time, reduces eye strain and turns everyday browsing into a hands-free audio experience. Since it still supports the standard read-aloud mode, you can switch back anytime.
Would you use AI hosts to read your favorite websites, or do you prefer the classic readback style? Let us know by writing to us at Cyberguy.com.
Using the new update powered by Google Gemini, you can change from the AI podcast to a simple word-for-word reading at any time. (“I’ve Had It” YouTube channel)
CLICK HERE TO DOWNLOAD THE FOX NEWS APP
Sign up for my FREE CyberGuy Report
Get my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox. Plus, you’ll get instant access to my Ultimate Scam Survival Guide — free when you join my CYBERGUY.COM newsletter.
Copyright 2025 CyberGuy.com. All rights reserved.
Technology
Even Trump’s chief of staff was ‘aghast’ at Elon Musk’s deadly USAID cuts
Wiles says she called Musk on the carpet. “You can’t just lock people out of their offices,” she recalls telling him. At first, Wiles didn’t grasp the effect that slashing USAID programs would have on humanitarian aid. “I didn’t know a lot about the extent of their grant making.” But with immunizations halted in Africa, lives would be lost. Soon she was getting frantic calls from relief agency heads and former government officials with a dire message: Thousands of lives were in the balance.
Wiles continued: “So Marco is on his way to Panama. We call him and say, ‘You’re Senate-confirmed. You’re going to have to be the custodian, essentially, of [USAID].’ ‘Okay,’ he says.” But Musk forged ahead—all throttle, no brake. “Elon’s attitude is you have to get it done fast. If you’re an incrementalist, you just won’t get your rocket to the moon,” Wiles said. “And so with that attitude, you’re going to break some china. But no rational person could think the USAID process was a good one. Nobody.”
-
Iowa2 days agoAddy Brown motivated to step up in Audi Crooks’ absence vs. UNI
-
Washington1 week agoLIVE UPDATES: Mudslide, road closures across Western Washington
-
Iowa1 week agoMatt Campbell reportedly bringing longtime Iowa State staffer to Penn State as 1st hire
-
Iowa4 days agoHow much snow did Iowa get? See Iowa’s latest snowfall totals
-
Cleveland, OH1 week agoMan shot, killed at downtown Cleveland nightclub: EMS
-
World1 week ago
Chiefs’ offensive line woes deepen as Wanya Morris exits with knee injury against Texans
-
Maine22 hours agoElementary-aged student killed in school bus crash in southern Maine
-
Technology6 days agoThe Game Awards are losing their luster