episode.ascii — live render

TL;DRHuman's Satori team discovered BADBOX, a scheme infecting off-brand Android TV boxes with Triada malware pre-shipment via supply chain compromise, enabling ad fraud (Peach Pit), residential proxies, and account takeover attacks across…

You can find all kinds of great deals on Android streaming TV boxes online. But sometimes something else comes in the box along with it. Our conversation with Lindsay Kaye – Vice President of Threat Intelligence at Human, and part of the security team that discovered that somewhere along the supply chain something else was getting installed into all kinds of Android devices.

Transcript

Machine-generated transcript; may contain errors.

Speaker 1: Back in 2019, this story broke about these Android phones. Since 2016, Google had been trying to root out what is now this very famous family of malware called Triada. Triada compromised Android devices and mostly used them for a bunch of, like, ad fraud stuff. It would compromise the device and secretly direct a bunch of traffic from the phone to a bunch of sites where the fraudulent traffic would be served real ads and the hackers would make money. And Google had been in this back and forth trying to root Triada out. They were going after insecurity updates, they locked down the Google Play Store a lot more, they're kinda just playing defense. And a few years in, in 2019, Google releases this kinda press release, almost a white paper. Basically about how they had figured out this new attack vector that hackers had been using to get Triada onto the devices. Something that until then had kind of managed to get around all of their new defenses. And it was no novel, because it wasn't a bad app someone could install, or really anything to do with the user. It had to do with the manufacturer. The malware was coming pre installed. Somewhere along the supply chain, at one of the many vendors and manufacturers, OEMs, and sub vendors who all had some small part in making the larger phone. Someone was installing this stuff. So the phones show up pre hacked. Google goes after that. They change how over air updates and power cycling works, they get tighter app controls, play protected certified Android devices become the norm in North America, And for a while, it looks like they mostly got it on phones.

Speaker 2: So I would say that criminals are always enterprising and financially motivated ones are always going to learn to make or figure out some way to make money.

Speaker 1: A while ago, this is an aside, I I had a conversation with a friend about piracy. And we did the thing where you add up how much you pay on streaming services. Well, how much I pay. He he does a lot of piracy. That's the point. Some people like streaming sites for piracy. Some people just torrent on a thing by thing basis. And some people use media servers. An app like Plex or Kodi running on either a PC or any kind of an Android streaming device, with then like plug in or otherwise access to a big server somewhere full of stolen stuff. My friend was one such person. And after our interview this episode, I texted him, hey, what's the thing you use for your whole home theater piracy rig? Like, what's what's the box itself? And he told me the name, and I said, I have some links for you. And they are they're bad news.

Speaker 2: So you're probably familiar, but one area in which Human specializes in is ad fraud.

Speaker 1: At the end of last year, some security researchers on the Satori team at Human noticed this weird traffic.

Speaker 2: Our team actually started, researching on some anomalous traffic signals that we're observing because we really wanna understand what could be causing them, and as a result, identified several related apps that seem to be causing them.

Speaker 1: And they traced the traffic back and realized a lot of it was connecting to this weird domain where they then

Speaker 2: Found some openly available research talking about a t 95 set top box, that the researchers saw also connected

Speaker 3: to that domain. So that was pretty interesting.

Speaker 1: And they figured out it had to do with Triada, the malware Google had spent years trying to root out of Android and largely had, from every Play Protect certified Android device, which is to say basically any phone or tablet you can buy from a store in a mall in North America or Europe. But not every Android device you can buy, because if right now, I were to go over to a large online retailer, and type in Android TV box, like the kind my buddy uses, well those are a totally different story. You have heard a couple quotes from our guest this episode. Lindsey Kaye, vice president of threat intelligence at Human. She is on the team that pulled on this threat and found that it led to a giant crazy scheme to break into the hardware manufacturing supply chain to find some point along that line where they could pre install this stuff. They called it Badbox. And the giant ad fraud scheme it empowers, that deluge of ad monetized fraudulent traffic, they named that Peach Pit. So Scott and I called up the Satori team to find out what exactly happened, how they busted it, and where it's all going next. Badbox, Peach Pit, and how hardware hackers are infiltrating supply chains, here on Hacked. Lindsay, thank you so much for sitting down to talk with us about this. Sure.

Speaker 2: Thank you so much for having me.

Speaker 1: I wanna start at what would have been the beginning of this for you and your team. What initially caught your team's attention? How did someone first come across the devices that were compromised by this?

Speaker 2: So you're probably familiar, but one area in which Heumann specializes in is ad fraud. So, we see various signals related to invalid traffic that might suggest ad frauds taking place. So as a result, as part of an investigation in November 2022, our team actually started, researching on some anomalous traffic signals that we're observing because we really wanna understand what could be causing them. And as a result, identified several related apps that seem to be causing them. So, in kind of our initial research, we suspected that the possible source of this invalid traffic was Android TV boxes, but really kinda needed to keep digging. So from there, one thing that we noticed is that these apps were connecting to a domain, flyermobi.com, which then we continue to dig into, sort of pivot on, look for, you know, any open source intelligence or other sorts of, I guess, apps or technology that was reaching out to it and found some openly available research talking about a t 95 set top box, that the researchers saw also connected

Speaker 3: to that domain. So that was

Speaker 2: pretty interesting. So what we want to do is we acquired a t 95 device and then as a result, confirm this research's findings that, oh my god, this t 95 device is compromised out of the box like they were talking about, and then corroborated our suspicions, about this flyer mobile domain. So at this point, now we had kind of two big pieces. So first, that invalid traffic that we'd first identified using our signals, and we call that eventually peach pit. And then that separate but related, operation with the implanted devices, called bad box. So those involved those Android TV boxes that were infected by this malware, known as Triata out of the box. And from there, what we did was we continued our research and identified additional devices containing this backdoor. And at this kind of the end of the research and right now, our estimate is that over 200 different device models may include it.

Speaker 1: Wow. Okay. So we have three different things at play here. We have the malware. This was infected with Triada. We've what you've labeled peach pit, which sounds like this anomalous ad fraud type traffic, and then we have the boxes themselves. I wanna I wanna start with the boxes because that's what made this really fascinating to me was this idea of I order something on the Internet, and it gets shipped to me preloaded with this malware. Tell me a bit about the t 95. Where can you buy these devices? Can you describe how they were being sold and distributed to customers? Let's zoom in on the box itself.

Speaker 2: So, devices like the t 95 and some of the other ones that we determined did have bad box on them are available widely. So you think about any sort of online retailers or any sort of brick and mortar stores, and our team is internationally located. So there's a wide variety of places that you could buy them. So, pretty much an almost anywhere. And then the interesting thing is that these are all so among the t 95 and the other ones that we looked at, these are off brand Android based mobile and connected TV devices. So not just the t 95, but several others and, you know, popular online retailers and resale sites. So pretty much all the bunch that you can I

Speaker 4: love I love that you're not naming it, but I think we all know who you're talking?

Speaker 1: But they're popular.

Speaker 5: They're popular online.

Speaker 2: Very easily accessible to, you know, you and I as average consumers, if we wanna kinda go out and buy any sort of off brand Android device, very easy to access.

Speaker 5: I got a I got a question. So in some of your documentation and blogging about this, you guys talked about iOS, traffic coming from Peach Pit. Is this malware existing on Apple TVs as well? Is that what that's indicative of?

Speaker 2: So I wanna kinda be very clear about, like, the difference between Badbox and Peach Pit. So Badbox is that, device that's infected with the Triada backdoor malware. We only ever saw that on Android devices. So no iOS devices were involved with that. So that was the Android, mobile CTV, Android off brand devices. And then, none of them were Google Play Protect. So that kinda gives you some idea of what I'm talking about there. For iOS, we only saw Peach Pit on that. So those were all applications that were available in the app. So I believe it was, 16 at that point where you can just, like, as a user, you go and you download them voluntarily. So kind of the difference between Badbox and Peachbit is Badbox, you're an unwitting consumer who ends up with this backdoor malware on your device. For the iOS apps, they might promise to be some game or some other kind of interesting utility that you as a user have to actively download. Does that help?

Speaker 5: Yeah. That helps helps greatly.

Speaker 1: For sure. So we have two different kind of pools of victims here, both of which are funneling traffic into this peach pit ad fraud, system.

Speaker 2: Yeah. So on, the majority of the bad box devices, so the soft brand and or devices, we did see, the peach pit module, downloaded. So kind of to give you some background here, once you boot up your newly acquired, let's say, CTV box, you put it on your network, the backdoor, the triadic component will reach out to a command and control server and then download some variety of modules. So the ad fraud module is what we call peach bit. So now you've kind of two sets of devices. Those Android devices that have Badbox that has, an unwittingly downloaded that peach pit module, and then you have, you know, Android and iOS devices that users are voluntarily going to the store and downloading these apps there. So the peach pit traffic that we're seeing could come from either set of those devices, some from the ones that came through Triada and then others that users were able to download from the app stores themselves.

Speaker 1: So once you're infected with these modules, either because you downloaded them from an App Store yourself or you bought a product that came pre shipped with them, take me through Peach Pit itself. This this module is in your system. What is it doing? What was the goal? What were the outcomes?

Speaker 2: So peach pit is if you're familiar with ad fraud, what it does is it has some sort of hidden advertisements, any sort of spoofed wood, Pravic, and malvertising. So, really, what this means is that, somebody wants to make money by either saying that they're showing advertisements and they're not actually showing them or pretending that an ad is shown to a user and not actually doing it. You might see things in other cases where they have a bunch of ads stacked on top of each other. So really what they're trying to do is say, yes, I'm showing these ads and then, be able to sort of make money sort of on the back end. And the one thing about the ones that are, app based, if you delete that app off of your phone, so your iOS or, Android phone, it's gone. And then no more ad fraud is occurring from that device. But you probably aren't even aware if you have one of those bad box devices that pull down that module in the background that this is even happening. So you're using your Android CTV device. You're kind of just off and merry, and it's, conducting that ad fraud in the background. And, unfortunately, there is not a simple and easy way, like, deleting an app to kinda get rid of that. So, unfortunately, for those a lot of those devices, you do actually have to, discard them.

Speaker 1: We, we spoke with the team over at Human a while ago about ad fraud, just trying to get our, lay of the land and a basic understanding of, like, what it was, how it worked, how it made the crazy volumes of money that it does make for the people that, perpetrate it. I'm struck by it seems like kind of an escalation to be shipping hardware products to people. This isn't just a question of a dodgy website you go to. This is like, no. You're actually getting into, like, a hardware supply chain in just in order to redirect ad fraud, like traffic towards ad fraud. Could you talk to us a little bit about why the scale of ad fraud would justify doing that? Because it seems like a really, really big undertaking to serve some fake ads to some fake eyeballs.

Speaker 2: Of course. So one thing I wanna be clear about is that the the actors who conducted peach pit are distinct from the bad box fed actors. So however those devices are being supply chained, you know, whether at the manufacturer or, point of sale or kind of between there somewhere, those individuals aren't necessarily the same people as the peach pit individuals. They are likely working together in some way because, obviously, if you think about it, if you're developing that peach pit module, and then you need to have it, you know, this backdoor reach out and then pull it down, there has to be some kind of interface there. But, it's based on some of the fact that we saw other types of modules associated with Badbox. So there's the residential proxy, and then there's the one time password module. That suggests that, you know, maybe they are monetizing that in some some entirely different way. So I wouldn't consider necessarily Badbox developed entirely to make this ad fraud peach pit stuff happen. It's possible that, you know, these other modules are able to be monetized in, another way as well to really kind of incentivize that, you know, backdooring of that hardware.

Speaker 1: Got it. So the bad box operation is getting malware onto these devices before they ship to you. Peach pock peach pit is simply one, way you could use that compromise.

Speaker 2: Correct.

Speaker 1: So can you take me through maybe some of the other stuff? You you gestured towards them just there in your last answer, but what other things, are these compromised bad box devices being used for?

Speaker 2: So we didn't, dig into that necessarily as much in some of that public reporting. We continue to kind of, you know, figure out sort of how the operation's changing, these days as well. But residential proxies. So, if you're not familiar for residential proxies, sometimes threat actors will actually, you know, use those because they wanna obscure some of where their traffic is coming from. So things like account takeover, any sort of credential stuffing attacks, you know, then the IPs look like they're coming from somebody's home IP rather than, from something that might be a little bit more worrisome if a company were to see it. So, this residential proxy part module that we observed, what happened was the user's bad box device, so off brand Android mobile and CTV devices only, were actually we saw them become nodes in a residential proxy. So, you can think about it. It's like, okay. Well, now what would somebody necessarily do with this this traffic? So it's something that a threat actor could, if they wanted to, sell access to other threat actors, to, you know, buy some of that residential proxy network access to do whatever it is that they want. But that is definitely another way of kind of thinking about it as well. The one time password, we're not entirely clear necessarily why, they would use that. We had some theories, but I don't believe it's as strong as kind of looking at some of that residential proxy.

Speaker 1: The other big prong of this k. I think I have a sense of Badbox versus Peach Pit, not just in terms of, like, how it affects people, but, you know, that these are two separate groups. In turn the last part of it is tryout of the malware. How should we understand that and all this?

Speaker 2: So Triata is that malware that makes these bad boxes bad boxes. They are the, backdoors. And in short, it's been around since 2016, So very long time. And then the best way to understand that is this Triadial malware, at some time between what's manufactured and given to retailers, is installed on those devices. And then as a result, different sort of modules are pulled down into it. So, basically, just kind of a simple backdoor. It only affects those non Google Play Protect Android devices, and it's something that a user wouldn't have any understanding of just by looking at the device. So we do at human have some idea of how to, you know, obviously, detect if a bad box is a bad box or not. But, you know, to the naked eye, it looks perfectly fine to anybody who's purchasing it. And there certainly are ways to make sure that you're not or make sure that you have less of a chance of buying a bad box. But it's something that, wouldn't be apparent if you just acquire versus those apps that conduct peach bit where if you have just the peach bit, you have to actively go out and download that app as a user from the App Store. You'd be fully aware that you were doing that.

Speaker 5: Got it. Apple's iTunes Store and the App Store is kind of known for rigorous controls, q and a on the, developer side. So, like, if you submit something with with bad code in it or something that doesn't meet Apple standards, they have a high rejection rate. I'm just wondering, you know, how they manage or if you know how they manage to get this malware into a bunch of iOS apps.

Speaker 2: So I truly don't, but we are, we have continued to work with Apple to make sure that, we've reported these apps and, you know, had them removed and explained to them how it works so that in the future, it's something that, you know, if they want to pursue as well, that's great. I know Google also has a very similar, similarly rigorous process now. I think it's less it's a little bit newer than maybe Apple's, but, we've worked heavily with them. We continue to work with them as needed.

Speaker 1: Gotcha. So somewhere along the supply chain, TriAuto gets installed in these devices. That's the vector for all this bad box stuff, which is bigger than just Peach Pit, but also includes the Peach Pit ad fraud network that you disrupted. I wanna talk about that disruption in a minute, but the part of this that I was really compelled by has to do with that moment in the supply chain, right, where that malware gets put onto these devices. I don't think I saw this specifically in the report. I'm kinda curious, where do you think that's happening? As a layperson, I'm buying something. At what point does it get compromised by this malware?

Speaker 2: So, truthfully, that's something that, we don't have any visibility into. Right? So

Speaker 1: It is.

Speaker 2: We, like, you know, anybody else buy these devices, often Sure. You know, a variety of these retailers. So we have no clue based on kind of when it was first manufactured up until then sort of what's happened to it. So, obviously, that's something that people might speculate about, but we have no insights. So, unclear.

Speaker 1: I mean, that brings up another interesting moment. What is it like buying these things? Like, you're kind of going fishing for a pretty bad fish, weird metaphor. But you you're having this thing shipped to you. Like, are you how do you silo it? How do you make sure that it doesn't mess anything up? Like, take me through the process of hitting buy on one of these things, getting it in the mail, and cracking it open.

Speaker 2: Sure. So, it's much like buying pretty much anything if you think about it. So like I like I said, that it's widely available, variety of retailers. You know, you go, you buy the device. Obviously, because of the signals that we're able to see associated with PageFit, that gave us some indication of, like, which devices should we target. So, give you a sense of, like, oh, okay. Maybe I'll buy one of these, one of those, one of the other things. Just kinda get a wide variety of devices. Obviously, my team has so many different devices now at their homes, related to this and some of the rest of our work. But, it's worth noting that, you know, if if you're receiving this device, you have to kind of assume that it's infected until you're sure that it is not. Just kind of a great way to treat all sort of malware like that. And then as I mentioned, we have a technique, based on a lot of what we've talked about in the report for determining if something is a bad box. So kind of looking for some of those IOCs, to figure out, you know, is this a bad box or not, but always treat it like a it is a bad box. You know, use good malware hygiene when you're doing your research, things like that.

Speaker 1: I, I guess I didn't really consider the possibility that once you've confirmed to a reasonable level of satisfaction that there's nothing wrong with this device, you could just take it home and use it as a TV set top box, but, like, the courage of plugging that in.

Speaker 2: Well, I would suggest, you know, obviously sticking to a lot of device the advice that, we've talked about. So Sure. Those Google Play Protect devices and, you know, buying only name brands and, you know, just being kind of really careful about what it is. So, you know, I would never, test the device, say, oh, it doesn't have a bad box on it. I'm good to go entirely. So just kind of treating research devices like they're research devices.

Speaker 1: Sure. Fair enough. Yeah. Before you take it home and log into Netflix with it and just just hope hope everything's okay. So can you give me a bit of a sense of the scale of this operation? Number of devices affected the geographical spread. How how how big is this thing we're talking about here right now?

Speaker 2: So at the peak, what we noticed is that there were an average of 4,000,000,000 requests a day, to that peach pit kind of ad fraud operation. Right? So 4,000,000 requests a day at its peak. And what we saw is a total of 280,000 devices infected. So that was a 121,000 Android devices and a 159,000 iOS devices. So across 227 countries and territories. So when I mentioned that, you know, this was definitely a global operation and it was affected, you know, a wide variety of individuals, like, that's entirely true.

Speaker 1: Starting some new isn't just hard. It can be downright terrifying. You put a lot of work into a thing. You're not entirely sure it's gonna work out. You're taking a huge leap of faith. I've started a few things. Now I know I was right for believing in, you know, the idea, the product, despite all of those fears and hesitations. But boy, does it sure help when you have a partner like Shopify on your side. Shopify is the commerce platform behind millions of businesses around the world and 10% of all e commerce in The US. From household names like, well, hacked podcasts merch, to brands just getting started, you can get started with your own design studio with hundreds of ready to use templates. Shopify helps you build a beautiful online store that matches your brand style. Did I mention that that iconic purple shop pay button is used by millions of businesses around the world? I don't know why I wouldn't. I should. It's why Shopify has the best converting checkout on the planet. It also helps boost conversions, meaning less carts, sort of getting abandoned in the parking lot, and more sales for you. It's time to turn those what ifs into sign up for your $1 per month trial at shopify.com/hacked. Go to shopify.com/hacked. One more time, that's shopify.com/hacked.

Speaker 4: Whatever your thing, it could be anything. Canva helps you make that thing a thing. Canva is a simple online tool thing. It's a way to design with our magic AI tool things. You can social media your thing, generate images or videos of your thing, make decks or presentations to show your thing. Whatever needs to be done for your thing, Canva can make it an even better and bigger thing. Canva, the thing that makes anything a thing.

Speaker 3: Study and play. Come together on a Windows 11 PC. And for a limited time, college students get the best of both worlds. Get the Unreal College Seal, everything you need to study and play with select Windows 11 PCs. Eligible students get a year of Microsoft three sixty five premium and a year of Xbox Game Pass Ultimate with a custom color Xbox wireless controller. Learn more at windows.com/studentoffer. While supplies last, ends June 30, terms at aka.ms/collegepc.

Speaker 6: Thinking about refreshing the carpet in your home? Now's the time to do it. For a limited time at The Home Depot, get 10% off installed carpet projects on trusted brands like Lifeproof, Lifeproof with PetProof Technology, Home Decorators Collection, and Traffic Master. Plus, with installation starting at just 49¢ per square foot, upgrading your space is more affordable than ever at The Home Depot. Offer valid 06/11/2026 through 06/28/2026. Exclusions apply for licenses. See homedepot.com/license numbers.

Speaker 1: You talked a little bit about the residential proxies and some of the other stuff happening on the bad box devices. But from, like, a victim perspective, what kind of impact did these vulnerabilities have on their privacy and security, the people that were using these devices? Do you have a sense of that?

Speaker 2: So, if you think about it, any device that necessarily like this has a backdoor to it. If somebody is able to discover it or how it works or subvert it in some way, obviously, that opens up users to risks. We didn't identify that happening in any of the devices that we saw. But, you know, if you have to think about it, there are certainly ways that people can convert a lot of these different types of devices. I think kind of at the more, you know, topic level, right, though, I think this report impacted consumers who now are starting to think about, like, their security. Right? Because it's like, you know, you would go on Internet, you'd buy a device, you would plug it in. But now I think this report really made people start to kinda think twice about that. It's like, what am I really buying? What am I really bringing into my home? You know? Right. These are things that certainly can happen, and I think this report opened some people's eyes to, oh my god. This is something that that can happen. Like, I had no idea, and then these devices can be just in my house. So maybe I should really kind of be a more, cognizant consumer of, you know, what it is that I am spending my money on and bringing in my home.

Speaker 1: I, as a brief aside, when I was reading about this story, prepping for this call, I was doing kind of a a little bit of, an accounting of everything that was connected to the Wi Fi network in my apartment. Because, boy, do you get paranoid when you read about this thing for long enough. And I just had this moment of, like, this giant exhale because a couple years ago, my partner and I bought a an automated cat feeder. And we were humming and hawing trying to decide between the Internet connected one and the the dumb version. And, I I just wanna let everyone know because I know you're all worried that we we bought the dumb one that doesn't connect to the Wi Fi network, off of Amazon, off of a very popular online retailer. So so as for now, I think I'm good.

Speaker 2: But see it really does make you think and it's like, oh my god. Let me go check what's on my on my network. So I think that you're not the only one probably.

Speaker 1: Well, I'm glad to hear that. In terms of okay. Let's let's get let's get to the good part. The disruption, the takedown. How did you go about that? What measures were taken? How did you start going about trying to disrupt part of this operation once you really had a full understanding of what it was that you were looking at?

Speaker 2: Sure. So after we identified where a lot of this traffic was coming from and had a good idea of what traffic signals were to block. So we started the investigation November. So in December 2022, we actually blocked the invalid traffic generated by the peach pit apps. So this is kind of that first step of the takedown. Kind of on the additional side there, as part of that peach pit ad fraud investigation, we actually identified those 20 apps in Google's Play Store and 17 apps and Apple's App Store that that were part of this operation, and then started working closely with Google and Apple teams to make sure that the apps, were reported and started getting taken down. So explaining a threat to them, you know, what is the impact, and then work with them to make sure that they got taken down. And no after continuing to monitor and work with our partners to see what peach pit was doing, making sure that volume was reduced as we expected it to, and remain mitigated. If we needed to, we could've certainly kind of continued and modified and stuff like that. So that's kind of on the peach pit side. So that's that takedown there where we really have a lot of that same visibility and sort of power to do that. But if you look at that box, human doesn't have that same ability to really directly disrupt it in the same way. Because if you think about, you know, how is the smell we're getting on, you know, how how is it affected, how could it even come off if it because it cannot. So it's interesting to kinda see, you know, outside of what human can control. You know, if you look at what's been happening since, it seems like the the report that we actually put out was effectively part of that disruption there for the bad box stuff. So looking kind of at some of the stuff that the industry is doing. So I don't know if you saw, but in November 2023, EFF actually wrote a letter to the FTC, that urged them to take action in stopping a resale of these infected Android television set top boxes and mobile devices. So they named, I believe, Allwinner and Rockchip devices, by different retailers. So the letter actually cited humans report on Badbox and gave a brief technical explanation based on the report. And And they talked a little bit about the consequences of reseller inaction at the brisket consumers. So while it's human is not directly taking down bad box, it's like steps like these really start to make people think. And, you know, when it comes to it, getting that sort of letter to the FTC is really powerful. Sort of we also saw actually an Australian retailer pull out all the t 95 boxes that they were, selling. So immediately based on our research. So it's like these kinds of small steps that are being taken, by retailers and by kind of government and things like that in The US is actually really interesting. And I don't know if you've had a chance to look on any of the online retailers. You can see that, some of the devices are actually being renamed. So not kind of the names that they were being sold under before, which suggests that maybe maybe their device sales could have been affected in some way based on the publication of our report or maybe they read our report even. We can't say for sure exactly how it happened or what happened, but that's definitely interesting. And, you know, we continue to work with industry partners. So many different channels because we want to address this kind of threat. So not the same direct kind of impact and to do the takedown that we did with the peach bit, but we do continue to work to this day.

Speaker 1: I'm struck by how whoever manufactures the t 95 is not necessarily a participant in any of these. I'm struck by the fact that that device is still for sale on a popular online retailer. How how would you suggest people think about purchasing these devices? Let's maybe go there. How would you imagine someone would stay safe knowing that any number of these, you know, Internet set top boxes on popular online retailers might be compromised.

Speaker 2: Sure. So I would recommend, if you have a choice, make sure that you kind of recognize the benefit of sticking to those well known recognized brands of hardware devices wherever possible. So, for example, like those bad box devices were not Play Protect certified. So that's something that, you know, if you have a choice between buying an off brand non certified device versus one that is does kinda have that certification, which, you know, says that it is safe, I would go with the safe one. Right? So I'm sure there's kind of some cost benefit to buying those off brand devices, but like we've kind of seen, we really don't have insight just by looking into it. Like, looking at it physically, like, if something could be wrong with it. You know, Triada is just one example of potential malware. So I would say trying to, you know, buy only devices that sort of meet that threshold and that name brand kind of recognition, if possible.

Speaker 5: Aside from just set top boxes, that's obviously the focus of the bad boxes. Jordan and I were recently discussing. I bought a new washing machine, had to buy a new washing machine is a better way to put it. And it it's got a essentially a small computer, and it connects to my IoT network, the whole nine. The now that there's, like, a small computer and everything, you know, do you do you see the potential for the same kind of attack trajectory to kind of play out through so many other Internet of Things devices? Or is it like do you see the set top boxes as being a bit of a unique appliance that that allows for this?

Speaker 2: So I believe other researchers for at least the past several years have talked about some of the vulnerabilities and dangers of some IoT devices. So this is not necessarily a new a new thing that has emerged. Like I'd mentioned, Triad has been around since 2016. So ever since then, it's like, okay. Well, there are obviously more opportunities for threat actors if they want to do something to a device. Do I know specifically how and which and whether it'll be an ad fraud thing? No. But if you kind of, you know, Google, you know, IoT malware, you can see other reports of people who have identified kind of similar but different threats related to some of those smart devices.

Speaker 1: I guess just to wrap up, you know, this is our second conversation with y'all about ad fraud. The first one was lay of the land and, you know, it was mostly about web traffic. This is a sort of novel, version of that with this this hardware compromise. In terms of ad fraud, where do you think this goes next? What is the escalation? What if you had to speculate on, like, the new attack vector of 2024, like, where do you think this is all going?

Speaker 2: So I would say that criminals are always enterprising and financially motivated ones are always going to learn to make or figure out some way to make money. So like I mentioned, things like Badbox and this peach pit were just kind of one example of ad fraud and then supply chain, devices. But if you look, it's some of the techniques that they have are still working. So what we do often see is, you know, they might have one operation. Let's say researchers, we figure it out, we write about it, we get rid of it. They'll just modify it a little bit to kind of work to evade detections. So I think we'll see more kind of around things like those residential proxies and kind of that monetization of some of this data. We'll probably see them, you know, slightly tweak some of that, the ways that they do ad fraud. Because, really, it is just kind of like the rest of cybersecurity, almost a cat and mouse game. Right?

Speaker 5: So, you

Speaker 2: know, you're a criminal. You make your your malware. Researchers find it and they stop it. You tweak it slightly. They find it again. So it just kinda keeps going like that. You know, they will have their operation. Let's say it gets taken down, disband, rebrand, and keep going. So

Speaker 1: and you'll be there to to keep to keep playing the, the cat and mouse game.

Speaker 2: Yes. Absolutely.

Speaker 5: Did you guys have the ability to, did you ever trace back or or geographically kind of identify where a lot of this traffic or the origin of this malware had come from?

Speaker 2: So in terms of where the infected devices were or in terms of where Peach Pit and Bad Box were?

Speaker 5: In terms of where Peach Pit and Bad Box were.

Speaker 2: Okay. So, currently, we believe that the Bad Box operation was based out of China. One possibly one or many Chinese manufacturers being involved in building those devices. In terms of the threat actors conducting Peach Pit, we identified three different entities. Can't really say exactly where they are. But we did continue to work with law enforcement to, you know, make sure that they were aware, and could kind of deal with them appropriately.

Speaker 1: That's interesting because it kinda suggests that whoever those manufacturers were in China that were compromising with, Triada were almost like a vendor is the wrong word, but had a business relationship with whoever was operating peach pit. It's almost like you're sending up a satellite and we wanna put something on it. It's like you're sending out a compromised device. We'd like to include something with it.

Speaker 2: So like I mentioned, the actors conducting Peach Pit are distinct from the bad box set actors. Are they likely working together in some way? Probably. But truthfully, we don't actually know where any of those entities, are located besides, you know, we what we believe and what we think. And we don't have any kind of, you know, clear, irrefutable evidence of how exactly they are connected.

Speaker 1: Fascinating. Lindsay, thank you so much for sitting down with us to talk about this. It's a very interesting one.

Speaker 2: Awesome. Thank you so much for having me. I really enjoyed it.

Speaker 5: Yeah. Thanks for coming

Speaker 3: on.