September 13, 2023, 3:19 pm | Read time: 4 minutes
Malware has been repeatedly discovered in inexpensive Android TV boxes–most of them from China. Users must fear for their personal data.
As early as May 2023, there were numerous reports of malware on Android TV boxes. Specifically, the reports focused on devices with chips from manufacturers AllWinner and RockChip. These companies’ TV boxes are quite popular on Amazon because they are inexpensive and highly customizable. However, experts discovered that the devices were shipped with pre-installed malware. Now, more models are affected. TECHBOOK explains the software’s operation and how to protect yourself.
Overview
Security Expert Discovers Malware on Own Android TV Box
In fact, the problem has been known for even longer. At the beginning of the year, security researcher Daniel Milisic discovered pre-installed malware on an Android TV box he purchased from Amazon. Specifically, it was the T95 model, which contains the AllWinner H616 chip–and this was infected. This could enable coordinated cyberattacks, among other things.
Milisic wanted to install the Pi-Hole software on the box and uncovered how much malware was pre-installed. At that time, it was still unclear whether it might be an isolated case. However, in May, similar reports about other Android TV boxes increased. All affected devices came from Chinese manufacturers. The malware is pre-installed from the factory.
To avoid confusion: While the devices are sold as “Android TV” boxes, the software is not signed by Google. Instead, the infected boxes use the open-source version of Android, which allows manufacturers to modify the box individually. Even installing apps from the Play Store is possible, and Chromecast is supported. The installed interface looks like Android TV–but it is not.
What Does the Malware Do?
As Milisic noted in January, the infected chips communicate in the background with so-called command-and-control servers, allowing hackers to send further commands to the devices. The malware-infected Android TV boxes form an extensive botnet, through which attackers can execute large-scale attacks.
A primary goal of the malware seems to be generating ad revenue by opening massive amounts of ads in the background. However, Milisic told the tech magazine TechCrunch: “Due to the way the malware is designed, the authors can distribute any payload they want.” And that is what makes it so dangerous.
The larger the botnet, the more dangerous the attacks. Hackers can not only cripple entire websites with denial-of-service attacks (DoS) but also spread further malware that, for example, captures personal data.
Other experts confirmed Milisic’s observations. Security researcher Bill Budington also found that his Android TV box was shipped with malware. The device came from Amazon, but the same model can also be purchased from other online retailers like AliExpress.
New Warnings About Malware on Android TV
The current warnings report a different malware–but it concerns the same devices. The new malware botnet is called Mirai and was discovered by Dr. Web, as reported by 4KFilme. According to the report, the Android TV boxes Tanix TX6 TV Box, MX10 Pro 6K, and H96 MAX X3 are among those affected.
Dr. Web’s antivirus team states that the malware in the new cases either arrived on the Android TV boxes via malicious apps or was again pre-installed from the factory.
WhatsApp Is Now Becoming a Malware Trap Here
These Digital Picture Frames Pose a Real Risk
How to Protect Yourself
Security expert Milisic already found with his own box that the average user cannot do much against the malware. The best course of action for those affected is to simply dispose of the box. The problem is that many probably do not even know they are affected.
Experts are already warning against purchasing such inexpensive TV boxes. Ensure you buy a certified device–in this case, from Google. Milisic also calls for higher security standards from manufacturers and sellers. Regarding online retailers like Amazon, the expert told TechCrunch: “You can’t sell children’s toys made of spinning razor blades. So why is it okay for small, unknown sellers to sell computers that act maliciously without the owner’s knowledge and consent?”
Sources
- TechCrunch (“Popular Android TV boxes sold on Amazon are laced with malware,” accessed September 13, 2023)
- 4KFilme (“Wieder Malware in billigen Android TV-Boxen aus China entdeckt,” accessed September 13, 2023)
- Golem (“Android-TV-Box mit vorinstallierter Schadsoftware gekauft,” accessed September 13, 2023)
- Reddit (accessed September 13, 2023)