Unlocking the DNS Strongbox of BADBOX 2.0 | WhoisXML API

Unlocking the DNS Strongbox of BADBOX 2.0

BADBOX 2.0 has reportedly infected more than 1 million consumer devices as of March 2025. And the subsequent attacks (e.g., click fraud, account takeovers [ATOs], distributed denial-of-service [DDoS] attacks, etc.) that may ensue aided by the botnet may affect millions more.1

WhoisXML API analyzed 109 indicators of compromise (IoCs) related to the threat and found more domains and IP addresses that could be part of the BADBOX 2.0 network. Our DNS deep dive led to the discovery of:

  • 915 email-connected domains, eight of which turned out to be malicious
  • 50 IP addresses, 34 of which have already been weaponized for attacks
  • 211 IP-connected domains
  • 2,078 string-connected domains, two of which have already been associated with a threat

Download a sample of the threat research materials now or contact sales to discuss your intelligence needs for threat detection and response or other cybersecurity use cases.

  • [1] https://www.humansecurity.com/learn/blog/satori-threat-intelligence-disruption-badbox-2-0/
Try our WhoisXML API for free
Get started