Security

Popular Android TV boxes sold on Amazon are laced with malware

Comment

A screenshot of Android TV, with television shows and movies selectable on screen
Image Credits: TechCrunch

AllWinner and RockChip might not be household names, but the two China-based companies power several wildly popular Android TV boxes that are sold on Amazon.

These Android-powered television set-top boxes are typically cheap and are highly customizable, packing several streaming services into a single device, rather than buying separate hardware. Their listings on Amazon boast four-out-of-five star ratings and collectively racked up thousands of praiseworthy reviews.

But security researchers say the models are sold preloaded with malware capable of launching coordinated cyberattacks.

Last year, Daniel Milisic bought an AllWinner T95 set-top box and discovered the chip’s firmware was infected with malware. Milisic found that the Android-powered set-top box was communicating with command and control servers and awaiting instructions on what to do next. His ongoing investigation, which he published on GitHub, found that his T95 model was out-of-the-box connecting to a larger botnet of thousands of other malware-infected Android TV boxes in homes and offices across the globe.

Milisic said the malware’s default payload is a clickbot, essentially code that generates ad money by surreptitiously tapping on ads in the background. After the affected Android TV boxes are powered on, the preloaded malware immediately contacts a command and control server, obtains its instructions of where to find the malware it needs, and pulls additional payloads to the device that carries out the ad-click fraud.

“But because of the way the malware is designed, the authors can push out any payload they like,” Milisic told TechCrunch.

EFF security researcher Bill Budington independently confirmed Milisic’s findings after also buying an affected device from Amazon. Several other AllWinner and RockChip Android TV models are also preloaded with the malware, including the AllWinner T95Max, RockChip X12 Plus, and RockChip X88 Pro 10.

a screenshot of the AllWinner T95 listed on Amazon
A screenshot of the AllWinner T95 listed on Amazon. Image Credits: TechCrunch (screenshot)

Botnets are usually made up of hundreds, if not thousands or millions, of compromised devices around the world. The operators behind the botnet can use this vast malicious network for mining cryptocurrency on an affected device, stealing data (if any) from the device or the network it’s connected to or harnessing the collective internet bandwidth from these devices to pummel other websites and internet servers with junk traffic, known as a distributed denial-of-service attack, knocking them offline.

Milisic asked the internet company hosting the command and control servers that dished out instructions to the wider botnet to pull those servers offline, and the servers hosting the ad-click malware disappeared a short time after. He warned, though, that the botnet could come back at any time with new infrastructure.

It’s not clear how large the botnet is. “It’s difficult to quantify the scale of this network,” Budington told TechCrunch. “What we do know is that everywhere we look there are different variants of Android trojan malware downloading next-stage malware from the same set of IPs, ones that have been involved in supply-chain attacks in the past. It’s an impressive and unsettling operation.”

Milisic and Budington note that there’s no easy way to remove the malware for the average user. Throwing out the box altogether might be the best option for affected users.

“I think the only way to mitigate this problem is to hold retailers to a higher standard,” Milisic told TechCrunch. Referring to online sellers like Amazon, “they’re not allowed to sell children’s toys made out of spinning razor blades, why is it OK to let small, unknown vendors sell computers acting maliciously without owners’ knowledge and permission?”

When reached by TechCrunch, Amazon spokesperson Adam Montgomery declined to say if Amazon reviews the security of the devices it sells or if it plans to remove from sale the malware-containing devices in question.

AllWinner and RockChip did not return requests for comment.

There has been a push in recent years to improve the standards of hardware security. The Biden administration said it plans to roll out a labeling system for internet-connected devices this year as part of efforts to encourage device makers to improve their device security, such as adding update mechanisms to patch security flaws. In 2018, California passed a law that bans internet-connected devices from using default and easy-to-guess passwords, which bad actors often use to hack into devices and ensnare them into a botnet.

At the time of writing, the affected AllWinner and RockChip models are still available for sale on Amazon.

US to launch ‘labeling’ rating program for internet-connected devices in 2023

More TechCrunch

We’ve been covering US-based Insurtech startup FAYE way back since 2022 with its Seed round, and the Series A round in 2023, and it seems they continue to be on…

Packing travel insurance products into an app helped FAYE to a $31M Series B

Sennder is acquiring the European ground transportation assets of logistics giant C.H. Robinson.

Sennder buys CH Robinson’s European business

When Egyptian B2B e-commerce platform Cartona last raised money in 2022, global and local investors were eager to invest in African startups solving the supply chain and operational challenges for…

Egypt’s Cartona raises $8.1M even as investors pull back from B2B e-commerce in Africa

During an emergency hearing held by the South Korean government, Young-bae Ku, Qoo10’s founder said he would secure the amount over the next 30 days.

Qoo10’s CEO pledges personal assets worth $58M to compensate Korean merchants affected by its liquidity crisis

Zoe sends customers at-home testing materials to collect blood or feces to test blood fat, blood sugar, and gut microbiome health. Following those results, the company scores every food (on…

Zoe, a microbiome-focused nutrition company, raises $15 million to expand in the U.S.

Qualcomm has launched the Snapdragon 4s Gen 2 chip to 5G smartphones in the sub-$100 price segment in India and other emerging markets.

Qualcomm’s new Snapdragon chip aims to bring 5G to sub-$100 devices

Users will be able to get the first taste of Apple Intelligence as Apple has started to make some of the features of its AI suite available with the iOS…

Apple brings Apple Intelligence with iOS 18.1 dev beta, but there are a lot of limitations

Canva has acquired Leonardo.ai, a generative AI content and research startup, as the company looks to broaden the scope of its AI tech stack. The financial terms of the deal…

Canva acquires Leonardo.ai to boost its generative AI efforts

The U.S. Commerce Department has issued a new report endorsing open models like Meta’s Llama 3.1, which it says promote competition.

New U.S. Commerce Department report endorses ‘open’ AI models

Shared micromobility giant Lime is piloting two new vehicles designed to appeal to women and older folks who might appreciate a lower step-through frame, smaller wheels and an upgrade from…

Lime is piloting two new e-bikes to attract more women and older riders 

Apple has published a technical paper detailing the models that it developed to power Apple Intelligence, the range of generative AI features headed to iOS, macOS and iPadOS over the…

Apple says it took a ‘responsible’ approach to training its Apple Intelligence models

A fireside chat on Monday between Nvidia CEO Jensen Huang and Meta CEO Mark Zuckerberg at the SIGGRAPH 2024 conference in Colorado took a few unexpected turns. It started innocently…

Huang and Zuckerberg swapped jackets at SIGGRAPH 2024 and things got weird

Meta’s machine learning model, Segment Anything, has a sequel: It now takes the model to the video domain, showing how fast the field is moving.

Zuckerberg touts Meta’s latest video vision AI with Nvidia CEO Jensen Huang

Featured Article

The fall of EV startup Fisker: A comprehensive timeline

Here is a timeline of the events that led fledgling automaker Fisker to file for bankruptcy.

The fall of EV startup Fisker: A comprehensive timeline

Hello, and welcome back to TechCrunch Space. In case you missed it, Boeing and NASA decided to keep Starliner docked to the International Space Station for the rest of the…

TechCrunch Space: Catching stars

As failed EV startup Fisker winds its way through bankruptcy, a persistent and tricky question has become a flashpoint of the proceedings: does its only secured lender, Heights Capital Management,…

The question haunting Fisker’s bankruptcy

So-called “unlearning” techniques are used to make a generative AI model forget specific and undesirable info it picked up from training data, like sensitive private data or copyrighted material. But…

Making AI models ‘forget’ undesirable data hurts their performance

Uber is now letting riders in India book up to three rides simultaneously.

Uber now lets users in India book three trips at once

U.S. airports are rolling out facial recognition to scan travelers’ faces before boarding their flights. Americans, at least, can opt out. 

How to opt out of facial recognition at airports (if you’re American)

The promise of AI and large language models (LLMs) is the ability to understand increasingly wider amounts of context and make sense of that information easily, so it makes sense…

Bee AI raises $7M for its wearable AI assistant that learns from your conversations

Featured Article

DEI backlash: Stay up-to-date on the latest legal and corporate challenges

It’s clear that this year will be a turning point for DEI.

DEI backlash: Stay up-to-date on the latest legal and corporate challenges

Bike-taxi startup Rapido, which counts Swiggy among its investors, is the latest Indian firm to become a unicorn.

India’s Rapido becomes a unicorn with fresh $120M funding

Government websites aren’t known for cutting-edge tech. GovWell co-founder and CTO Ben Cohen discovered this while trying to help his dad, a contractor, apply for building permits. Cohen worked as…

GovWell is bringing automation and efficiency to local governments

Critics have long argued that wararantless device searches at the U.S. border are unconstitutional and violate the Fourth Amendment.

US border agents must get warrant before cell phone searches, federal court rules

Featured Article

UK’s Zapp EV plans to expand globally with an early start in India

Zapp is launching its urban electric two-wheeler in India in 2025 as it plans to expand globally.

UK’s Zapp EV plans to expand globally with an early start in India

The first time I saw Google’s latest commercial, I wondered, “Is it just me, or is this kind of bad?” By the fourth or fifth time I saw it, I’d…

Dear Google, who wants an AI-written fan letter?

Featured Article

MatPat, the first big YouTuber to successfully exit his company, is lobbying for creators on Capitol Hill

Though MatPat retired from YouTube, he’s still pretty busy. In fact, he’s been spending a lot of time on Capitol Hill.

MatPat, the first big YouTuber to successfully exit his company, is lobbying for creators on Capitol Hill

Featured Article

A tale of two foldables

Samsung is still foldables’ 500-pound gorilla, but the company successes have made the category significantly less lonely in recent years.

A tale of two foldables

The California Department of Motor Vehicles this week granted Nuro approval to test its third-generation R3 autonomous delivery vehicle in four Bay Area cities, giving the AV startup a positive…

Autonomous delivery startup Nuro is gearing up for a comeback

With Ghostery turning 15 years old this month, TechCrunch caught up with CEO Jean-Paul Schmetz to discuss the company’s strategy and the state of ad tracking.

Ghostery’s CEO says regulation won’t save us from ad trackers