Unlocking the DNS Strongbox of BADBOX 2.0
BADBOX 2.0 has reportedly infected more than 1 million consumer devices as of March 2025. And the subsequent attacks (e.g., click fraud, account takeovers [ATOs], distributed denial-of-service [DDoS] attacks, etc.) that may ensue aided by the botnet may affect millions more.1
WhoisXML API analyzed 109 indicators of compromise (IoCs) related to the threat and found more domains and IP addresses that could be part of the BADBOX 2.0 network. Our DNS deep dive led to the discovery of: