Threat Intelligence Disruption: BADBOX 2.0 Targets Consumer Devices with Multiple Fraud Schemes
HUMAN's Satori team uncovered and partially disrupted BADBOX 2.0, a complex fraud operation targeting over 1 million low-cost consumer devices worldwide. The scheme involves a backdoor pre-installed on devices or distributed through unofficial app marketplaces, allowing threat actors to conduct various fraudulent activities. These include selling residential proxy services, ad fraud through hidden ads and WebViews, and click fraud. Four main threat actor groups were identified: SalesTracker, MoYu, Lemon, and LongTV. The operation affects Android Open Source Project devices in 222 countries, with Brazil being the most impacted. Disruption efforts involved collaboration with Google and other partners to mitigate the threat's impact.
AI Analysis
Technical Summary
BADBOX 2.0 is a sophisticated fraud campaign uncovered by HUMAN's Satori team that targets over one million low-cost consumer devices globally, primarily those running on the Android Open Source Project (AOSP). The threat actors behind BADBOX 2.0 leverage a backdoor that is either pre-installed on devices during manufacturing or distributed through unofficial app marketplaces. This backdoor enables multiple fraudulent activities, including the sale of residential proxy services, ad fraud via hidden advertisements and WebViews, and click fraud. The operation is orchestrated by at least four distinct threat actor groups named SalesTracker, MoYu, Lemon, and LongTV. The campaign's reach is extensive, affecting devices in 222 countries, with Brazil identified as the most impacted region. The backdoor facilitates covert control and communication with command and control servers, enabling the execution of various tactics such as proxy service abuse (T1071.001), ad fraud (T1608, T1608.001), and botnet activities (T1104). The disruption efforts involved collaboration between HUMAN, Google, and other partners to mitigate the threat's impact, including domain takedowns and blocking malicious infrastructure. Despite the disruption, the campaign highlights the risks associated with low-cost consumer devices that may lack robust supply chain security and the dangers of unofficial app marketplaces. BADBOX 2.0 exemplifies how compromised consumer devices can be weaponized for large-scale fraud operations, leveraging the scale and diversity of IoT and Android ecosystems.
Potential Impact
For European organizations, BADBOX 2.0 poses indirect but significant risks. While the primary targets are consumer devices, the widespread use of compromised devices as residential proxies and botnets can facilitate attacks against European enterprises by masking attacker origins and enabling large-scale fraud campaigns. The ad fraud and click fraud components can distort digital advertising metrics, impacting European businesses relying on online marketing. Additionally, compromised devices within European networks could be leveraged as footholds for lateral movement or as part of broader botnet operations, potentially affecting network performance and security. The presence of backdoors on consumer devices also raises privacy and data protection concerns under regulations like GDPR, as unauthorized data exfiltration or device manipulation could occur. The disruption of BADBOX 2.0 reduces immediate risk, but the underlying vulnerabilities in supply chains and device ecosystems remain a concern for European consumers and organizations relying on these devices.
Mitigation Recommendations
European organizations should implement several targeted measures beyond generic advice: 1) Enhance supply chain security by vetting device manufacturers and insisting on secure firmware and software development practices to prevent pre-installed backdoors. 2) Educate consumers and employees about the risks of installing apps from unofficial marketplaces and encourage the use of official app stores with vetted applications. 3) Deploy network monitoring tools capable of detecting anomalous proxy traffic and unusual outbound connections indicative of residential proxy abuse or botnet activity. 4) Collaborate with ISPs and cybersecurity communities to identify and block malicious command and control domains associated with BADBOX 2.0. 5) Incorporate threat intelligence feeds related to BADBOX 2.0 indicators into security operations to enable proactive detection and response. 6) For organizations involved in digital advertising, implement fraud detection mechanisms to identify and mitigate ad fraud and click fraud activities. 7) Advocate for and support regulatory frameworks that enforce stricter security standards for IoT and consumer devices sold within Europe.
Affected Countries
Germany, France, United Kingdom, Italy, Spain, Netherlands, Poland, Belgium, Sweden, Finland
Indicators of Compromise
- domain: 1ztop.work
- domain: admoyu.com
- domain: ads-goal.com
- domain: ai-goal.com
- domain: astrolink.cn
- domain: bltproxy.com
- domain: bluefish.work
- domain: bullet-proxy.com
- domain: cbpheback.com
- domain: cpbheback.com
- domain: cxlcyy.com
- domain: cxzyr.com
- domain: dazzl.vip
- domain: easyjoy.me
- domain: echojoy.xyz
- domain: firehub.link
- domain: firehub.work
- domain: fuhidd.com
- domain: giddy.cc
- domain: huulog.com
- domain: huuww.com
- domain: ipforyou.top
- domain: jasmine.land
- domain: jolted.vip
- domain: joyfulxx.com
- domain: jutux.work
- domain: logcer.com
- domain: meisvip.com
- domain: moonhub.work
- domain: motiyu.net
- domain: moyix.com
- domain: msohu.online
- domain: msohu.shop
- domain: mtcpmpm.com
- domain: mtcprogram.com
- domain: mtcpuouo.com
- domain: net-goal.com
- domain: pccyy.com
- domain: pcxrlback.com
- domain: petrel-ip.com
- domain: pixelscast.com
- domain: pixlo.cc
- domain: pm2za.cc
- domain: qulogger.com
- domain: randomhow.com
- domain: retrofitxer.com
- domain: rzless.work
- domain: shanhulan.cn
- domain: simplekds.me
- domain: soyatea.online
- domain: supportdatainput.top
- domain: swiftcode.work
- domain: sysbinder.com
- domain: tvsnapp.com
- domain: veezy.site
- domain: vividweb.work
- domain: vmud.net
- domain: wildpettykiwi.com
- domain: wildpettykiwi.xyz
- domain: wotads.com
- domain: ycxad.com
- domain: ycxrldow.com
- domain: yeyeyeye.xyz
- domain: yxcrl.com
- domain: yydsma.com
- domain: yydsmb.com
- domain: yydsmd.com
- domain: ztword.com
- domain: zxcvbnmasdfghjkl.xyz
- domain: 179wg.com
- domain: 1day.gift
- domain: 24kgames.com
- domain: aashe.online
- domain: accesshealthworldwide.org
- domain: acrenews.top
- domain: acruy.fun
- domain: adstormsurge.com
- domain: adxtocloud.com
- domain: agilenovax.com
- domain: ailgame.com
- domain: aimogame.com
- domain: aimoongames.com
- domain: airecer.com
- domain: airsignswind.com
- domain: al260.com
- domain: alaskak.com
- domain: algerieancienne.com
- domain: alphagames.top
- domain: amarlyn.com
- domain: amenkingdj.com
- domain: americagame.top
- domain: announce.group
- domain: antonng.com
- domain: antplay.fun
- domain: arcadeatlas.pro
- domain: arisy.fun
- domain: arking.fun
- domain: ashgame.top
- domain: ashimay.com
- domain: astagames.com
- domain: autogame.top
- domain: avicled.com
- domain: axiominvest.top
- domain: balconygame.com
- domain: balecrina.com
- domain: banagames.com
- domain: bathgamer.com
- domain: bdeath.com
- domain: beauty-meow.com
- domain: beavergamer.com
- domain: begoniagames.com
- domain: benlux.fun
- domain: berryplaytime.com
- domain: biugames.com
- domain: bjsvp50.space
- domain: blendergamer.com
- domain: blissfultop.top
- domain: bluejoy.fun
- domain: blunt.fun
- domain: bluutian.com
- domain: bniz.top
- domain: boffo5.org
- domain: bonfuns.com
- domain: bravegamey.com
- domain: breadmbutter.com
- domain: breastliftusa.icu
- domain: brighlttips.com
- domain: brightinfu.com
- domain: broomgamer.com
- domain: btownmagic.com
- domain: buttgamer.com
- domain: buygame.top
- domain: buzynews.com
- domain: buzzingnews246.top
- domain: buzzingnow.top
- domain: buzzlynews.com
- domain: buzztub.site
- domain: bytenews.xyz
- domain: cacylide.com
- domain: calagame.com
- domain: calfgames.com
- domain: calrnner.com
- domain: canball.fun
- domain: cancercuisine.top
- domain: cardforecast.top
- domain: care-9478143.xyz
- domain: carsgame.top
- domain: casualgame.fun
- domain: caterpillargame.com
- domain: causecentural.com
- domain: ccaixa.com
- domain: ceedgame.top
- domain: celestialechoes.top
- domain: ceregame.com
- domain: championbkt.com
- domain: cheekgames.com
- domain: cheestgame.com
- domain: chewygame.com
- domain: chupgame.com
- domain: cidanfinance.com
- domain: cinthhy.com
- domain: clbtw.com
- domain: clearinfe.com
- domain: clevory2.com
- domain: coatgames.com
- domain: cocolans.fun
- domain: compao.com
- domain: cooldeal.fun
- domain: crazyfantasygame.com
- domain: crazyjoy.fun
- domain: crispplay.com
- domain: cryptogamef.com
- domain: cubicgames.top
- domain: culinarydreams.top
- domain: cupgamer.com
- domain: custgame.com
- domain: customcommercialcranes.icu
- domain: cutgamer.com
- domain: daareco.com
- domain: dailygames.top
- domain: dailyhumor.top
- domain: dailynewsfunny.top
- domain: davegas-casino-online.com
- domain: days4.com
- domain: dceuneb.com
- domain: dddyizhan.com
- domain: delienanch.com
- domain: delishcravings56.top
- domain: delishnoms777.top
- domain: delishorse.com
- domain: depargame.com
- domain: dependgames.com
- domain: destinyjoy.fun
- domain: detergame.com
- domain: detergames.com
- domain: developidea.space
- domain: dianhualife.com
- domain: diceygames.top
- domain: digacoupon.com
- domain: digifuseinfo.com
- domain: digressgames.com
- domain: dinjoy.fun
- domain: dipvy.com
- domain: dispgame.com
- domain: ditizhan.com
- domain: divvo.net
- domain: domaingame.top
- domain: domengame.com
- domain: domipa.com
- domain: dorky7.org
- domain: draingamer.com
- domain: dreamcraftxpress.top
- domain: dreamyscope.top
- domain: dreamytranq.com
- domain: drumgamer.com
- domain: dryergames.com
- domain: dulegames.com
- domain: dustpangame.com
- domain: earthsignse.com
- domain: echoloot.pro
- domain: econotrend.us
- domain: elitegamey.com
- domain: elitgameu.com
- domain: elitnewsy.com
- domain: elixeryinfo.com
- domain: elkgame.com
- domain: empresaderestauracindeviviendas.icu
- domain: enchantnovels99.top
- domain: epicenewspro.com
- domain: epicnarrative.top
- domain: epicplayr.top
- domain: europegame.top
- domain: evdenevdenevenakliyatgroup.icu
- domain: eventplanningservice.icu
- domain: exactgames.top
- domain: expertisetip.com
- domain: eyebrowgamer.com
- domain: eyris.fun
- domain: fabricgamer.com
- domain: facelifttreatments.icu
- domain: fanciestfood.com
- domain: fateplay.fun
- domain: favstarlord.com
- domain: fayrib.fun
- domain: feedsrocafort.com
- domain: fictionplanet.top
- domain: financialknowledge.online
- domain: financitime.com
- domain: finger-game.com
- domain: firebytegaming.top
- domain: fixgamey.com
- domain: flavorburst.top
- domain: flavorfrenzytop.top
- domain: flavorfulfiction.top
- domain: focusgame.top
- domain: fofopub.fun
- domain: foodhunters.top
- domain: foodiefables123.top
- domain: foodiefiesta.top
- domain: foodiemagicbox.top
- domain: foodiemaster.top
- domain: foodiequest.top
- domain: foodietopreads.top
- domain: footgamer.com
- domain: forkliftgearrental.icu
- domain: forkliftsrental.icu
- domain: fosugufen.com
- domain: fourleafcookies.com
- domain: fridayol.com
- domain: fun-goal.com
- domain: funchat.ai
- domain: funfiction567.top
- domain: funforge.site
- domain: funny-playing.com
- domain: funnygamespot.com
- domain: funquest1010.top
- domain: fununiverse789.top
- domain: funzone2play.top
- domain: fuplayer.com
- domain: fusegamer.com
- domain: game-global.site
- domain: gamecatter.com
- domain: gamechampion.top
- domain: gamechampionx.top
- domain: gamecooky.com
- domain: gamefever2023.top
- domain: gamefinder.cc
- domain: gamefooo.com
- domain: gamehate.com
- domain: gameheatwave.com
- domain: gamehunterrealm.top
- domain: gameine.com
- domain: gamekite.cc
- domain: gamelocker.site
- domain: gamelov.online
- domain: gamelucy.com
- domain: gamemaster999.top
- domain: gamematrixtop.top
- domain: gamemaximus.top
- domain: gamement.cc
- domain: gamemini.fun
- domain: gamenewstales.top
- domain: gamenewswire.top
- domain: gameorbit.pro
- domain: gameprime1.top
- domain: gameprimex.top
- domain: gamepulsepro.top
- domain: gamepupu.com
- domain: gameraven.top
- domain: gamercander.com
- domain: gamerealmquest.top
- domain: gameregions.com
- domain: gameretroarcade.top
- domain: gamerplay005.space
- domain: gamerplay59.space
- domain: gamerwin.cc
- domain: gamescape.site
- domain: gamesgame.top
- domain: gamesh5.co
- domain: gameslnv.com
- domain: gamesplusx.com
- domain: gamestation.top
- domain: gametoptidings.top
- domain: gamevant.com
- domain: gamevaults.top
- domain: gamewatermelon.com
- domain: gamewave.us
- domain: gaminggoing.xyz
- domain: gamingjoy111.top
- domain: gamingnest.top
- domain: gamingnewsjoy.top
- domain: gamingupdates.top
- domain: gammygamef.com
- domain: gamxtasy.com
- domain: gardeniagames.com
- domain: garybell.co.uk
- domain: gearedforgamers.com
- domain: gentealn.com
- domain: ggcyeah.fun
- domain: ghgqfzqlhw.com
- domain: gogjoy.fun
- domain: gomboy.com
- domain: gooocatty.com
- domain: grapearcade.com
- domain: guanacogame.com
- domain: guidestek.com
- domain: h5gameapp.com
- domain: h5gameweb.top
- domain: h5playzone.com
- domain: hairlyfairy.com
- domain: hairskintransplant.icu
- domain: hairtransplantspecialist.icu
- domain: hamgamer.com
- domain: hamgaming.com
- domain: hampergame.com
- domain: hampergames.com
- domain: hazygame.top
- domain: heartgames.top
- domain: heatfungame.com
- domain: helplessgame.com
- domain: hexwin.fun
- domain: hiddenpizzagames.com
- domain: hkpuzzlegame.pro
- domain: hockeygames.top
- domain: hollywoodnation.net
- domain: homeconstructionllc.icu
- domain: homeconstructions.icu
- domain: homeconstructionservices.icu
- domain: hopgameu.com
- domain: hot9game.com
- domain: hotchipsgame.com
- domain: hoth5.top
- domain: humbertohah.com
- domain: hunkgame.top
- domain: huqigame.com
- domain: ideaechoes.top
- domain: idlemaze.com
- domain: ikesotou.com
- domain: indiantrainstatus.com
- domain: infinitytop.top
- domain: infohivex.com
- domain: inforokplus.com
- domain: innfuns.com
- domain: innovanetinfo.com
- domain: insurancegame.top
- domain: intellix.top
- domain: investaifuture.com
- domain: investdiary.top
- domain: jacperhos.com
- domain: jaeergame.com
- domain: jamgame.top
- domain: jazzy4.org
- domain: jigsawl.com
- domain: jinewoo.com
- domain: jino.fun
- domain: jo2yx.com
- domain: jokez.fun
- domain: joyfulnovels1.top
- domain: jtp42.com
- domain: jumblefunny.com
- domain: jumbogames.top
- domain: jumboinsur.com
- domain: junglygames.top
- domain: jzird.com
- domain: keelgames.top
- domain: keengames.top
- domain: kgw21.com
- domain: khod.top
- domain: khyu.top
- domain: kimiz.fun
- domain: kittyjoy.fun
- domain: kneepainspecialists.icu
- domain: knowinggames.top
- domain: koeppwealth.com
- domain: kog-goal.com
- domain: kvop.top
- domain: ladeaccot.com
- domain: lagegame.com
- domain: laserhairtransplant.icu
- domain: latestnewser.top
- domain: laughterzone.top
- domain: lavagamer.com
- domain: leadonegame.com
- domain: lengergames.top
- domain: lightpaly.com
- domain: linkinfox.com
- domain: lintgame.com
- domain: liplenty.com
- domain: lipsgorgeous.com
- domain: lividgamey.com
- domain: loan-3346973.info
- domain: lobgamer.com
- domain: loftjoy.fun
- domain: lollyroom.top
- domain: lopub.fun
- domain: luggame.com
- domain: lunggamer.com
- domain: luno.fun
- domain: magekeo.com
- domain: magicjourney123.top
- domain: mancures.com
- domain: marouchoc.com
- domain: maszzi.com
- domain: mazingtour.com
- domain: mazygame.top
- domain: measurgame.com
- domain: mentgame.com
- domain: minigame.ink
- domain: minigameae.com
- domain: miyogame.top
- domain: mobgame.pro
- domain: mollias.com
- domain: mongchaigame.com
- domain: moorick.com
- domain: mopgamer.com
- domain: mowergame.com
- domain: mubacare.com
- domain: mustgamer.com
- domain: myhtmlcode.com
- domain: navelgame.com
- domain: naxru.top
- domain: ndsgame.top
- domain: nebulegames.top
- domain: neckgames.com
- domain: nefetair.com
- domain: netplay.fun
- domain: newfld.com
- domain: newinfostops.com
- domain: newsbuzz.top
- domain: newsbuzzhub.top
- domain: newsbuzztop.top
- domain: newsechoesworld.com
- domain: newsflash246.top
- domain: newsflashers.top
- domain: newsfuninsight.top
- domain: newsjungle.top
- domain: newsmakers246.top
- domain: newsspotz.com
- domain: newstopfictionv.top
- domain: newstoptales.top
- domain: newswonderful.com
- domain: newtongame.com
- domain: nhaya.fun
- domain: nicekeptgame.com
- domain: nicelovinggame.com
- domain: nicheshu.com
- domain: nikejoy.fun
- domain: noodlesd.com
- domain: novelmagic.top
- domain: novelmagic123.top
- domain: novelquesttop.top
- domain: novelwizards.top
- domain: nuggetsgame.com
- domain: oceantwirl.com
- domain: odysseyhorizon.top
- domain: offlinequiz.com
- domain: oilswaterseparator.icu
- domain: omac.fun
- domain: onwardgames.top
- domain: oop-goal.com
- domain: optifuelknow.com
- domain: opyaon.fun
- domain: or938.com
- domain: organgame.com
- domain: organgame.top
- domain: originweb.xyz
- domain: ovalgames.top
- domain: oxhug.fun
- domain: oyute.com
- domain: packagegame.com
- domain: part-time-jobs-4794711.zone
- domain: partridgegames.com
- domain: pastaties.com
- domain: pdflight.com
- domain: peagamer.com
- domain: peaknewsf.com
- domain: peoapp.net
- domain: pepach.com
- domain: peraic.dev
- domain: perksgame.com
- domain: pheasantgames.com
- domain: pilrimage.com
- domain: pinup-yeni-adresi-mobi.com
- domain: pinupcasinoguncelgiris.com
- domain: pinupyeniadresimobi.com
- domain: pixarz.com
- domain: pixelquestarena.fun
- domain: pixelsprout.lol
- domain: platgamer.com
- domain: playblisshub.com
- domain: playcoxen.pro
- domain: playcubicle.com
- domain: playenemygamer.com
- domain: playfulgamefun.top
- domain: playfulquest12.top
- domain: playhivez.top
- domain: playmasteshr.top
- domain: playport.site
- domain: playshichang.com
- domain: playtopia.pro
- domain: playwarrior.top
- domain: plovergames.com
- domain: pluslikeplay.com
- domain: pluszgames.com
- domain: pokerjoy.fun
- domain: politicxinfo.com
- domain: polywo.com
- domain: popcar.fun
- domain: poping.fun
- domain: poptour.top
- domain: poshgames.top
- domain: possfinance.com
- domain: postergamer.com
- domain: povcar.top
- domain: powerplayz.cc
- domain: ppogame.com
- domain: prahaluv.com
- domain: pretgame.com
- domain: pretydeni.com
- domain: progamemaster.top
- domain: progamerz.top
- domain: proofgames.top
- domain: puregygame.com
- domain: purplepeacockbyneera.com
- domain: puzzleplaza.pro
- domain: puzzlid.com
- domain: qcggow.com
- domain: qsadewnt.com
- domain: quadgames.top
- domain: quanitumgamer.com
- domain: quantrichy.com
- domain: quantumcodrise.us
- domain: quantumrisehub.top
- domain: quickplaypro.top
- domain: quickwinning.top
- domain: quirk5.com
- domain: quirkytests101.top
- domain: quizgeek789.top
- domain: quizwhiz1010.top
- domain: quizzytests101.top
- domain: qxcsf.com
- domain: radianttop.top
- domain: rakegames.com
- domain: rapidgamez.com
- domain: rapidogame.com
- domain: ravergames.com
- domain: realestategame.top
- domain: realmnova.com
- domain: redbudgames.com
- domain: redhotter.com
- domain: redtamatofeed.com
- domain: resergame.com
- domain: reunbot.com
- domain: rezzgame.top
- domain: rianglo.com
- domain: rightgamer.com
- domain: rosygameu.com
- domain: rpeditnews.com
- domain: rubyburst.com
- domain: runcel.fun
- domain: ruoopsharo.com
- domain: rustinvest.top
- domain: sagafish.top
- domain: samofinance.com
- domain: savoryplanet.top
- domain: sciencehub.online
- domain: scoutsgamer.com
- domain: screenstouch.com
- domain: secgamer.com
- domain: seedsgames.com
- domain: semi-fire.com
- domain: serbakuis.com
- domain: serenenews.com
- domain: sh-mogu.com
- domain: shedgamer.com
- domain: shenghuijuzhifeng.top
- domain: shiftyturn.com
- domain: shinygamey.com
- domain: showergamer.com
- domain: shrubsgame.com
- domain: shrubsgames.com
- domain: siclegame.com
- domain: simulationgame.xyz
- domain: sinel.fun
- domain: sinkgamer.com
- domain: sitegrab.xyz
- domain: slissam.com
- domain: sloup.top
- domain: smartgamey.com
- domain: snakegamer.com
- domain: softenergame.com
- domain: solareclipsex.top
- domain: solargames.top
- domain: solitudetop.top
- domain: sparkgamet.com
- domain: sparkgamey.com
- domain: sparkinfoy.com
- domain: sparknewsz.com
- domain: speedgamer.top
- domain: stainlesssteelmanufacturersusa.icu
- domain: starcrest.top
- domain: starglowingx.top
- domain: starguide.top
- domain: starlightly.top
- domain: starpowerinfo.top
- domain: stonegames.top
- domain: storygalaxy555.top
- domain: storysphere.top
- domain: storytellers12.top
- domain: storytime999.top
- domain: stovegamer.com
- domain: studiosnews.com
- domain: succstc.com
- domain: suedae.com
- domain: suitgamer.com
- domain: sumokata.com
- domain: sunrisegamey.com
- domain: sweatergamer.com
- domain: swiftaihubx.com
- domain: swiftflownews.com
- domain: swiftlytips.com
- domain: swifttipn.com
- domain: symdoom.com
- domain: syreafsgame.com
- domain: syyyym.com
- domain: tailbonetie.com
- domain: tailbontie.com
- domain: tamotoo.com
- domain: tanhcole.com
- domain: tarotdelighter.top
- domain: tarotfun567.top
- domain: tarotfunmania.top
- domain: tarotfunzonemagic.top
- domain: tarotgateway777.top
- domain: tarotguru888.top
- domain: tarotinsiders.top
- domain: tarotinsight55.top
- domain: tarotinsighter.top
- domain: tarotinsightful.top
- domain: tarotinsightser.top
- domain: tarotinspider.top
- domain: tarotjoygames.top
- domain: tarotmagicfun.top
- domain: tarotmastery.top
- domain: tarotmysterly.top
- domain: tarotmystics9.top
- domain: tarotrealm999.top
- domain: tarotrealmtop.top
- domain: tarottalesfun.top
- domain: tarotwonders89.top
- domain: tarotzone.top
- domain: tastefulstory.top
- domain: tastybites2022.top
- domain: tastydelites56.top
- domain: tastygamer.top
- domain: tastygourmetjoy.top
- domain: tastynomsdelightly.top
- domain: tastyorbits.top
- domain: tastytarotfoodv.top
- domain: techbyteinfo.com
- domain: techgane.com
- domain: techgyroinfo.com
- domain: techieinfoo.com
- domain: techiepoint.online
- domain: techinforoom.com
- domain: techybuilders.com
- domain: techygamezone.com
- domain: techyinfz.com
- domain: teckx.net
- domain: tel-goal.com
- domain: tenergame.com
- domain: testgeeklab.top
- domain: testjoywonder.top
- domain: testmaze.top
- domain: testplatform.top
- domain: testyourlimits.top
- domain: thegamehub.pro
- domain: thegamevista.com
- domain: thehighercontent.com
- domain: theshivalya.com
- domain: thesnarf.net
- domain: thighgame.com
- domain: thrivewellnessworld.com
- domain: tickgamer.com
- domain: tingo.fun
- domain: tinux.fun
- domain: tofix.fun
- domain: tombgame.com
- domain: tonglingxw.info
- domain: topnewswave24.top
- domain: topnewswave99.top
- domain: toppedgames.top
- domain: torygame.com
- domain: tpfxw.com
- domain: tradegame.top
- domain: tranquilinfo.com
- domain: traveltodeworld.com
- domain: tripletgames.com
- domain: trippher.com
- domain: trisscheng.com
- domain: tubeard.com
- domain: ugame.com
- domain: uptogamez.com
- domain: uptogane.com
- domain: url-app.com
- domain: utritontips.com
- domain: vastjoy.fun
- domain: vexing.fun
- domain: virtuacorner.com
- domain: viviangames.com
- domain: vividexsnews.com
- domain: vkim.top
- domain: voekgame.com
- domain: voidgames.top
- domain: vopfit.com
- domain: vopos.fun
- domain: vousgame.com
- domain: vowt.top
- domain: vrshoppinggame.com
- domain: vvivireal.com
- domain: wackygames.top
- domain: wadadeis.com
- domain: waddleplayer.ink
- domain: waistgames.com
- domain: waoshow.com
- domain: wardgamer.com
- domain: washgamer.com
- domain: watermarkcamera.com
- domain: waves.ink
- domain: weaponscuriosa.com
- domain: widegames.top
- domain: windjoy.fun
- domain: wirelessgame.top
- domain: wisdomgames.top
- domain: wishself.com
- domain: wociyu.com
- domain: woffty.fun
- domain: wokgamer.com
- domain: wonderfulgames.top
- domain: wooolgame.com
- domain: workingusa.net
- domain: wowenjoys.com
- domain: xenicgames.top
- domain: xqbdh66.com
- domain: xylofy.com
- domain: yintao02.com
- domain: yongo.fun
- domain: yummybooks.top
- domain: yummyeats888.top
- domain: yuyibld.com
- domain: zeldagame.top
- domain: zentraxtips.com
- domain: zentrixinfo.com
- domain: zesttipsz.com
- domain: zhidagame.com
- domain: zinkgame.top
- domain: zinko.top
- domain: zippygamez.com
- domain: zlon.fun
- domain: zontime.com
- domain: 8083.play.quizzop.com
- domain: 8085.read.newszop.com
- domain: 8aa1ba05.rushquiz.com
- domain: ab.oxhug.fun
- domain: ab.tingo.fun
- domain: ab.wishself.com
- domain: abs.fun-goal.com
- domain: aft.fofopub.fun
- domain: aft.lopub.fun
- domain: am.fofopub.fun
- domain: am.oxhug.fun
- domain: am.popcar.fun
- domain: am.tingo.fun
- domain: anc.fofopub.fun
- domain: anc.fun-goal.com
- domain: arcade.funforge.site
- domain: as.tingo.fun
- domain: aug26h.liveingame.com
- domain: ax.runcel.fun
- domain: bg.netplay.fun
- domain: bg.tingo.fun
- domain: brand.minigame.vip
- domain: bsc.ai-goal.com
- domain: c.misffgame.com
- domain: cdn.ai-goal.com
- domain: de.registrea.com
- domain: des.fun-goal.com
- domain: des.luno.fun
- domain: dwz.cocolans.fun
- domain: dwz.naxru.top
- domain: dwz.opyaon.fun
- domain: dwz.popcar.fun
- domain: dwz.poping.fun
- domain: dwz.povcar.top
- domain: dwz.wishself.com
- domain: dwz.zinko.top
- domain: e06zh.merifall.com
- domain: electricvehiclefans.faberk.com
- domain: erp.onceisnotenough.ca
- domain: extra.minigame.vip
- domain: f.gameleb.com
- domain: f.swiftflexa.com
- domain: fashion.firenzeire.com
- domain: film.minigame.vip
- domain: finance.insightivetip.com
- domain: finance.misffgame.com
- domain: finance.phriao.com
- domain: finance.quixoteinfo.com
- domain: food.vibrantews.com
- domain: fun.biugames.com
- domain: g1.h5game1.com
- domain: g1.toolol.top
- domain: game.aialeek.com
- domain: game.bliscanemon.com
- domain: game.boomgamef.com
- domain: game.brighugame.com
- domain: game.cactiapi.com
- domain: game.dromeling.com
- domain: game.echoloot.pro
- domain: game.fernetari.com
- domain: game.hexwin.fun
- domain: game.knighzgame.com
- domain: game.legendgamey.com
- domain: game.mindflexa.com
- domain: game.newsavenuey.com
- domain: game.noclemoon.com
- domain: game.playbuzz.online
- domain: game.returnlitnews.com
- domain: game.rnalaler.com
- domain: game.sereneevoke.com
- domain: game.smartgamey.com
- domain: game.snookershow.com
- domain: game.tuusonit.com
- domain: game.zhengxuitnews.com
- domain: game01.chipandgames.com
- domain: game02.chipandgames.com
- domain: gas.sinel.fun
- domain: ge.opyaon.fun
- domain: get.minigame.cool
- domain: gfun.ai-goal.com
- domain: goodac.dailynewscome.com
- domain: gpdz.jzfreegames.com
- domain: gphb.ravergames.com
- domain: gym.zingoinfo.com
- domain: hd04.gamesgarden.info
- domain: health.troquerde.com
- domain: hhm.lolagamers.com
- domain: hot.calfgames.com
- domain: how.tel-goal.com
- domain: insurance.quixoteinfo.com
- domain: invest.fincoin.top
- domain: led06.gamesgarden.info
- domain: nc.acruy.fun
- domain: nc.fofopub.fun
- domain: nc.nhaya.fun
- domain: nc.sloup.top
- domain: nc.tel-goal.com
- domain: news.aimoongames.com
- domain: news.healthute.com
- domain: nk.axtun.fun
- domain: nk.bluejoy.fun
- domain: nk.crazyjoy.fun
- domain: nk.destinyjoy.fun
- domain: nk.fun-goal.com
- domain: nk.luno.fun
- domain: nk.poping.fun
- domain: nk.povcar.top
- domain: nk.sloup.top
- domain: nk.tel-goal.com
- domain: nk.tingo.fun
- domain: nk.tinux.fun
- domain: nk.vastjoy.fun
- domain: nk.wishself.com
- domain: nk.woffty.fun
- domain: np.acruy.fun
- domain: np.tinux.fun
- domain: ns.ai-goal.com
- domain: nszc.rokiread.com
- domain: ob.povcar.top
- domain: ob.windjoy.fun
- domain: opt.fofopub.fun
- domain: ph.fofopub.fun
- domain: play.arking.fun
- domain: play.ashgame.top
- domain: play.echoloot.pro
- domain: play.fun-goal.com
- domain: play.funforge.site
- domain: play.h5gameapp.com
- domain: play.hot9game.com
- domain: play.kimgame.com
- domain: play.oxhug.fun
- domain: rdm.tinux.fun
- domain: rw.axtun.fun
- domain: rw.oxhug.fun
- domain: rw.tofix.fun
- domain: rw.zlon.fun
- domain: s.povcar.top
- domain: s1.digifuseinfo.com
- domain: search.googledouble.top
- domain: sokida.games4html5.com
- domain: sokida.lopsgame.com
- domain: sokida.peelgames.com
- domain: ss.tinux.fun
- domain: stylaxu.trendenclave.com
- domain: teun09.gamesgarden.info
- domain: totoro029.jzfreegames.com
- domain: totoro040.jzfreegames.com
- domain: travel.cightingle.com
- domain: travel.cleverinfy.com
- domain: travel.seviotive.com
- domain: ttq1.liveingame.com
- domain: tx.lopub.fun
- domain: ubt.oxhug.fun
- domain: ubt.popcar.fun
- domain: ubt.poping.fun
- domain: ubt.sloup.top
- domain: ubt.zinko.top
- domain: vogxu.hairsalonparkerco.com
- domain: w.axtun.fun
- domain: w.sinel.fun
- domain: wtg.sinel.fun
- domain: wtg.tingo.fun
- domain: yc.gamesgoplay.com
- domain: yc.h5cloudgame.com
- domain: yc.lolagamers.com
- domain: ym.nhaya.fun
- domain: ym.runcel.fun
- domain: ym.tel-goal.com
- domain: zc.lolagamers.com
Threat Intelligence Disruption: BADBOX 2.0 Targets Consumer Devices with Multiple Fraud Schemes
Description
HUMAN's Satori team uncovered and partially disrupted BADBOX 2.0, a complex fraud operation targeting over 1 million low-cost consumer devices worldwide. The scheme involves a backdoor pre-installed on devices or distributed through unofficial app marketplaces, allowing threat actors to conduct various fraudulent activities. These include selling residential proxy services, ad fraud through hidden ads and WebViews, and click fraud. Four main threat actor groups were identified: SalesTracker, MoYu, Lemon, and LongTV. The operation affects Android Open Source Project devices in 222 countries, with Brazil being the most impacted. Disruption efforts involved collaboration with Google and other partners to mitigate the threat's impact.
AI-Powered Analysis
Technical Analysis
BADBOX 2.0 is a sophisticated fraud campaign uncovered by HUMAN's Satori team that targets over one million low-cost consumer devices globally, primarily those running on the Android Open Source Project (AOSP). The threat actors behind BADBOX 2.0 leverage a backdoor that is either pre-installed on devices during manufacturing or distributed through unofficial app marketplaces. This backdoor enables multiple fraudulent activities, including the sale of residential proxy services, ad fraud via hidden advertisements and WebViews, and click fraud. The operation is orchestrated by at least four distinct threat actor groups named SalesTracker, MoYu, Lemon, and LongTV. The campaign's reach is extensive, affecting devices in 222 countries, with Brazil identified as the most impacted region. The backdoor facilitates covert control and communication with command and control servers, enabling the execution of various tactics such as proxy service abuse (T1071.001), ad fraud (T1608, T1608.001), and botnet activities (T1104). The disruption efforts involved collaboration between HUMAN, Google, and other partners to mitigate the threat's impact, including domain takedowns and blocking malicious infrastructure. Despite the disruption, the campaign highlights the risks associated with low-cost consumer devices that may lack robust supply chain security and the dangers of unofficial app marketplaces. BADBOX 2.0 exemplifies how compromised consumer devices can be weaponized for large-scale fraud operations, leveraging the scale and diversity of IoT and Android ecosystems.
Potential Impact
For European organizations, BADBOX 2.0 poses indirect but significant risks. While the primary targets are consumer devices, the widespread use of compromised devices as residential proxies and botnets can facilitate attacks against European enterprises by masking attacker origins and enabling large-scale fraud campaigns. The ad fraud and click fraud components can distort digital advertising metrics, impacting European businesses relying on online marketing. Additionally, compromised devices within European networks could be leveraged as footholds for lateral movement or as part of broader botnet operations, potentially affecting network performance and security. The presence of backdoors on consumer devices also raises privacy and data protection concerns under regulations like GDPR, as unauthorized data exfiltration or device manipulation could occur. The disruption of BADBOX 2.0 reduces immediate risk, but the underlying vulnerabilities in supply chains and device ecosystems remain a concern for European consumers and organizations relying on these devices.
Mitigation Recommendations
European organizations should implement several targeted measures beyond generic advice: 1) Enhance supply chain security by vetting device manufacturers and insisting on secure firmware and software development practices to prevent pre-installed backdoors. 2) Educate consumers and employees about the risks of installing apps from unofficial marketplaces and encourage the use of official app stores with vetted applications. 3) Deploy network monitoring tools capable of detecting anomalous proxy traffic and unusual outbound connections indicative of residential proxy abuse or botnet activity. 4) Collaborate with ISPs and cybersecurity communities to identify and block malicious command and control domains associated with BADBOX 2.0. 5) Incorporate threat intelligence feeds related to BADBOX 2.0 indicators into security operations to enable proactive detection and response. 6) For organizations involved in digital advertising, implement fraud detection mechanisms to identify and mitigate ad fraud and click fraud activities. 7) Advocate for and support regulatory frameworks that enforce stricter security standards for IoT and consumer devices sold within Europe.
For access to advanced analysis and higher rate limits, contact root@offseq.com
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://www.humansecurity.com/learn/blog/satori-threat-intelligence-disruption-badbox-2-0","https://www.humansecurity.com/wp-content/uploads/2025/03/BADBOX-2-H5-Domain-List.csv"]
- Adversary
- null
- Pulse Id
- 68434df5a7a61c7583cdec3f
- Threat Score
- null
Indicators of Compromise
Domain
Value | Description | Copy |
---|---|---|
domain1ztop.work | — | |
domainadmoyu.com | — | |
domainads-goal.com | — | |
domainai-goal.com | — | |
domainastrolink.cn | — | |
domainbltproxy.com | — | |
domainbluefish.work | — | |
domainbullet-proxy.com | — | |
domaincbpheback.com | — | |
domaincpbheback.com | — | |
domaincxlcyy.com | — | |
domaincxzyr.com | — | |
domaindazzl.vip | — | |
domaineasyjoy.me | — | |
domainechojoy.xyz | — | |
domainfirehub.link | — | |
domainfirehub.work | — | |
domainfuhidd.com | — | |
domaingiddy.cc | — | |
domainhuulog.com | — | |
domainhuuww.com | — | |
domainipforyou.top | — | |
domainjasmine.land | — | |
domainjolted.vip | — | |
domainjoyfulxx.com | — | |
domainjutux.work | — | |
domainlogcer.com | — | |
domainmeisvip.com | — | |
domainmoonhub.work | — | |
domainmotiyu.net | — | |
domainmoyix.com | — | |
domainmsohu.online | — | |
domainmsohu.shop | — | |
domainmtcpmpm.com | — | |
domainmtcprogram.com | — | |
domainmtcpuouo.com | — | |
domainnet-goal.com | — | |
domainpccyy.com | — | |
domainpcxrlback.com | — | |
domainpetrel-ip.com | — | |
domainpixelscast.com | — | |
domainpixlo.cc | — | |
domainpm2za.cc | — | |
domainqulogger.com | — | |
domainrandomhow.com | — | |
domainretrofitxer.com | — | |
domainrzless.work | — | |
domainshanhulan.cn | — | |
domainsimplekds.me | — | |
domainsoyatea.online | — | |
domainsupportdatainput.top | — | |
domainswiftcode.work | — | |
domainsysbinder.com | — | |
domaintvsnapp.com | — | |
domainveezy.site | — | |
domainvividweb.work | — | |
domainvmud.net | — | |
domainwildpettykiwi.com | — | |
domainwildpettykiwi.xyz | — | |
domainwotads.com | — | |
domainycxad.com | — | |
domainycxrldow.com | — | |
domainyeyeyeye.xyz | — | |
domainyxcrl.com | — | |
domainyydsma.com | — | |
domainyydsmb.com | — | |
domainyydsmd.com | — | |
domainztword.com | — | |
domainzxcvbnmasdfghjkl.xyz | — | |
domain179wg.com | — | |
domain1day.gift | — | |
domain24kgames.com | — | |
domainaashe.online | — | |
domainaccesshealthworldwide.org | — | |
domainacrenews.top | — | |
domainacruy.fun | — | |
domainadstormsurge.com | — | |
domainadxtocloud.com | — | |
domainagilenovax.com | — | |
domainailgame.com | — | |
domainaimogame.com | — | |
domainaimoongames.com | — | |
domainairecer.com | — | |
domainairsignswind.com | — | |
domainal260.com | — | |
domainalaskak.com | — | |
domainalgerieancienne.com | — | |
domainalphagames.top | — | |
domainamarlyn.com | — | |
domainamenkingdj.com | — | |
domainamericagame.top | — | |
domainannounce.group | — | |
domainantonng.com | — | |
domainantplay.fun | — | |
domainarcadeatlas.pro | — | |
domainarisy.fun | — | |
domainarking.fun | — | |
domainashgame.top | — | |
domainashimay.com | — | |
domainastagames.com | — | |
domainautogame.top | — | |
domainavicled.com | — | |
domainaxiominvest.top | — | |
domainbalconygame.com | — | |
domainbalecrina.com | — | |
domainbanagames.com | — | |
domainbathgamer.com | — | |
domainbdeath.com | — | |
domainbeauty-meow.com | — | |
domainbeavergamer.com | — | |
domainbegoniagames.com | — | |
domainbenlux.fun | — | |
domainberryplaytime.com | — | |
domainbiugames.com | — | |
domainbjsvp50.space | — | |
domainblendergamer.com | — | |
domainblissfultop.top | — | |
domainbluejoy.fun | — | |
domainblunt.fun | — | |
domainbluutian.com | — | |
domainbniz.top | — | |
domainboffo5.org | — | |
domainbonfuns.com | — | |
domainbravegamey.com | — | |
domainbreadmbutter.com | — | |
domainbreastliftusa.icu | — | |
domainbrighlttips.com | — | |
domainbrightinfu.com | — | |
domainbroomgamer.com | — | |
domainbtownmagic.com | — | |
domainbuttgamer.com | — | |
domainbuygame.top | — | |
domainbuzynews.com | — | |
domainbuzzingnews246.top | — | |
domainbuzzingnow.top | — | |
domainbuzzlynews.com | — | |
domainbuzztub.site | — | |
domainbytenews.xyz | — | |
domaincacylide.com | — | |
domaincalagame.com | — | |
domaincalfgames.com | — | |
domaincalrnner.com | — | |
domaincanball.fun | — | |
domaincancercuisine.top | — | |
domaincardforecast.top | — | |
domaincare-9478143.xyz | — | |
domaincarsgame.top | — | |
domaincasualgame.fun | — | |
domaincaterpillargame.com | — | |
domaincausecentural.com | — | |
domainccaixa.com | — | |
domainceedgame.top | — | |
domaincelestialechoes.top | — | |
domainceregame.com | — | |
domainchampionbkt.com | — | |
domaincheekgames.com | — | |
domaincheestgame.com | — | |
domainchewygame.com | — | |
domainchupgame.com | — | |
domaincidanfinance.com | — | |
domaincinthhy.com | — | |
domainclbtw.com | — | |
domainclearinfe.com | — | |
domainclevory2.com | — | |
domaincoatgames.com | — | |
domaincocolans.fun | — | |
domaincompao.com | — | |
domaincooldeal.fun | — | |
domaincrazyfantasygame.com | — | |
domaincrazyjoy.fun | — | |
domaincrispplay.com | — | |
domaincryptogamef.com | — | |
domaincubicgames.top | — | |
domainculinarydreams.top | — | |
domaincupgamer.com | — | |
domaincustgame.com | — | |
domaincustomcommercialcranes.icu | — | |
domaincutgamer.com | — | |
domaindaareco.com | — | |
domaindailygames.top | — | |
domaindailyhumor.top | — | |
domaindailynewsfunny.top | — | |
domaindavegas-casino-online.com | — | |
domaindays4.com | — | |
domaindceuneb.com | — | |
domaindddyizhan.com | — | |
domaindelienanch.com | — | |
domaindelishcravings56.top | — | |
domaindelishnoms777.top | — | |
domaindelishorse.com | — | |
domaindepargame.com | — | |
domaindependgames.com | — | |
domaindestinyjoy.fun | — | |
domaindetergame.com | — | |
domaindetergames.com | — | |
domaindevelopidea.space | — | |
domaindianhualife.com | — | |
domaindiceygames.top | — | |
domaindigacoupon.com | — | |
domaindigifuseinfo.com | — | |
domaindigressgames.com | — | |
domaindinjoy.fun | — | |
domaindipvy.com | — | |
domaindispgame.com | — | |
domainditizhan.com | — | |
domaindivvo.net | — | |
domaindomaingame.top | — | |
domaindomengame.com | — | |
domaindomipa.com | — | |
domaindorky7.org | — | |
domaindraingamer.com | — | |
domaindreamcraftxpress.top | — | |
domaindreamyscope.top | — | |
domaindreamytranq.com | — | |
domaindrumgamer.com | — | |
domaindryergames.com | — | |
domaindulegames.com | — | |
domaindustpangame.com | — | |
domainearthsignse.com | — | |
domainecholoot.pro | — | |
domaineconotrend.us | — | |
domainelitegamey.com | — | |
domainelitgameu.com | — | |
domainelitnewsy.com | — | |
domainelixeryinfo.com | — | |
domainelkgame.com | — | |
domainempresaderestauracindeviviendas.icu | — | |
domainenchantnovels99.top | — | |
domainepicenewspro.com | — | |
domainepicnarrative.top | — | |
domainepicplayr.top | — | |
domaineuropegame.top | — | |
domainevdenevdenevenakliyatgroup.icu | — | |
domaineventplanningservice.icu | — | |
domainexactgames.top | — | |
domainexpertisetip.com | — | |
domaineyebrowgamer.com | — | |
domaineyris.fun | — | |
domainfabricgamer.com | — | |
domainfacelifttreatments.icu | — | |
domainfanciestfood.com | — | |
domainfateplay.fun | — | |
domainfavstarlord.com | — | |
domainfayrib.fun | — | |
domainfeedsrocafort.com | — | |
domainfictionplanet.top | — | |
domainfinancialknowledge.online | — | |
domainfinancitime.com | — | |
domainfinger-game.com | — | |
domainfirebytegaming.top | — | |
domainfixgamey.com | — | |
domainflavorburst.top | — | |
domainflavorfrenzytop.top | — | |
domainflavorfulfiction.top | — | |
domainfocusgame.top | — | |
domainfofopub.fun | — | |
domainfoodhunters.top | — | |
domainfoodiefables123.top | — | |
domainfoodiefiesta.top | — | |
domainfoodiemagicbox.top | — | |
domainfoodiemaster.top | — | |
domainfoodiequest.top | — | |
domainfoodietopreads.top | — | |
domainfootgamer.com | — | |
domainforkliftgearrental.icu | — | |
domainforkliftsrental.icu | — | |
domainfosugufen.com | — | |
domainfourleafcookies.com | — | |
domainfridayol.com | — | |
domainfun-goal.com | — | |
domainfunchat.ai | — | |
domainfunfiction567.top | — | |
domainfunforge.site | — | |
domainfunny-playing.com | — | |
domainfunnygamespot.com | — | |
domainfunquest1010.top | — | |
domainfununiverse789.top | — | |
domainfunzone2play.top | — | |
domainfuplayer.com | — | |
domainfusegamer.com | — | |
domaingame-global.site | — | |
domaingamecatter.com | — | |
domaingamechampion.top | — | |
domaingamechampionx.top | — | |
domaingamecooky.com | — | |
domaingamefever2023.top | — | |
domaingamefinder.cc | — | |
domaingamefooo.com | — | |
domaingamehate.com | — | |
domaingameheatwave.com | — | |
domaingamehunterrealm.top | — | |
domaingameine.com | — | |
domaingamekite.cc | — | |
domaingamelocker.site | — | |
domaingamelov.online | — | |
domaingamelucy.com | — | |
domaingamemaster999.top | — | |
domaingamematrixtop.top | — | |
domaingamemaximus.top | — | |
domaingamement.cc | — | |
domaingamemini.fun | — | |
domaingamenewstales.top | — | |
domaingamenewswire.top | — | |
domaingameorbit.pro | — | |
domaingameprime1.top | — | |
domaingameprimex.top | — | |
domaingamepulsepro.top | — | |
domaingamepupu.com | — | |
domaingameraven.top | — | |
domaingamercander.com | — | |
domaingamerealmquest.top | — | |
domaingameregions.com | — | |
domaingameretroarcade.top | — | |
domaingamerplay005.space | — | |
domaingamerplay59.space | — | |
domaingamerwin.cc | — | |
domaingamescape.site | — | |
domaingamesgame.top | — | |
domaingamesh5.co | — | |
domaingameslnv.com | — | |
domaingamesplusx.com | — | |
domaingamestation.top | — | |
domaingametoptidings.top | — | |
domaingamevant.com | — | |
domaingamevaults.top | — | |
domaingamewatermelon.com | — | |
domaingamewave.us | — | |
domaingaminggoing.xyz | — | |
domaingamingjoy111.top | — | |
domaingamingnest.top | — | |
domaingamingnewsjoy.top | — | |
domaingamingupdates.top | — | |
domaingammygamef.com | — | |
domaingamxtasy.com | — | |
domaingardeniagames.com | — | |
domaingarybell.co.uk | — | |
domaingearedforgamers.com | — | |
domaingentealn.com | — | |
domainggcyeah.fun | — | |
domainghgqfzqlhw.com | — | |
domaingogjoy.fun | — | |
domaingomboy.com | — | |
domaingooocatty.com | — | |
domaingrapearcade.com | — | |
domainguanacogame.com | — | |
domainguidestek.com | — | |
domainh5gameapp.com | — | |
domainh5gameweb.top | — | |
domainh5playzone.com | — | |
domainhairlyfairy.com | — | |
domainhairskintransplant.icu | — | |
domainhairtransplantspecialist.icu | — | |
domainhamgamer.com | — | |
domainhamgaming.com | — | |
domainhampergame.com | — | |
domainhampergames.com | — | |
domainhazygame.top | — | |
domainheartgames.top | — | |
domainheatfungame.com | — | |
domainhelplessgame.com | — | |
domainhexwin.fun | — | |
domainhiddenpizzagames.com | — | |
domainhkpuzzlegame.pro | — | |
domainhockeygames.top | — | |
domainhollywoodnation.net | — | |
domainhomeconstructionllc.icu | — | |
domainhomeconstructions.icu | — | |
domainhomeconstructionservices.icu | — | |
domainhopgameu.com | — | |
domainhot9game.com | — | |
domainhotchipsgame.com | — | |
domainhoth5.top | — | |
domainhumbertohah.com | — | |
domainhunkgame.top | — | |
domainhuqigame.com | — | |
domainideaechoes.top | — | |
domainidlemaze.com | — | |
domainikesotou.com | — | |
domainindiantrainstatus.com | — | |
domaininfinitytop.top | — | |
domaininfohivex.com | — | |
domaininforokplus.com | — | |
domaininnfuns.com | — | |
domaininnovanetinfo.com | — | |
domaininsurancegame.top | — | |
domainintellix.top | — | |
domaininvestaifuture.com | — | |
domaininvestdiary.top | — | |
domainjacperhos.com | — | |
domainjaeergame.com | — | |
domainjamgame.top | — | |
domainjazzy4.org | — | |
domainjigsawl.com | — | |
domainjinewoo.com | — | |
domainjino.fun | — | |
domainjo2yx.com | — | |
domainjokez.fun | — | |
domainjoyfulnovels1.top | — | |
domainjtp42.com | — | |
domainjumblefunny.com | — | |
domainjumbogames.top | — | |
domainjumboinsur.com | — | |
domainjunglygames.top | — | |
domainjzird.com | — | |
domainkeelgames.top | — | |
domainkeengames.top | — | |
domainkgw21.com | — | |
domainkhod.top | — | |
domainkhyu.top | — | |
domainkimiz.fun | — | |
domainkittyjoy.fun | — | |
domainkneepainspecialists.icu | — | |
domainknowinggames.top | — | |
domainkoeppwealth.com | — | |
domainkog-goal.com | — | |
domainkvop.top | — | |
domainladeaccot.com | — | |
domainlagegame.com | — | |
domainlaserhairtransplant.icu | — | |
domainlatestnewser.top | — | |
domainlaughterzone.top | — | |
domainlavagamer.com | — | |
domainleadonegame.com | — | |
domainlengergames.top | — | |
domainlightpaly.com | — | |
domainlinkinfox.com | — | |
domainlintgame.com | — | |
domainliplenty.com | — | |
domainlipsgorgeous.com | — | |
domainlividgamey.com | — | |
domainloan-3346973.info | — | |
domainlobgamer.com | — | |
domainloftjoy.fun | — | |
domainlollyroom.top | — | |
domainlopub.fun | — | |
domainluggame.com | — | |
domainlunggamer.com | — | |
domainluno.fun | — | |
domainmagekeo.com | — | |
domainmagicjourney123.top | — | |
domainmancures.com | — | |
domainmarouchoc.com | — | |
domainmaszzi.com | — | |
domainmazingtour.com | — | |
domainmazygame.top | — | |
domainmeasurgame.com | — | |
domainmentgame.com | — | |
domainminigame.ink | — | |
domainminigameae.com | — | |
domainmiyogame.top | — | |
domainmobgame.pro | — | |
domainmollias.com | — | |
domainmongchaigame.com | — | |
domainmoorick.com | — | |
domainmopgamer.com | — | |
domainmowergame.com | — | |
domainmubacare.com | — | |
domainmustgamer.com | — | |
domainmyhtmlcode.com | — | |
domainnavelgame.com | — | |
domainnaxru.top | — | |
domainndsgame.top | — | |
domainnebulegames.top | — | |
domainneckgames.com | — | |
domainnefetair.com | — | |
domainnetplay.fun | — | |
domainnewfld.com | — | |
domainnewinfostops.com | — | |
domainnewsbuzz.top | — | |
domainnewsbuzzhub.top | — | |
domainnewsbuzztop.top | — | |
domainnewsechoesworld.com | — | |
domainnewsflash246.top | — | |
domainnewsflashers.top | — | |
domainnewsfuninsight.top | — | |
domainnewsjungle.top | — | |
domainnewsmakers246.top | — | |
domainnewsspotz.com | — | |
domainnewstopfictionv.top | — | |
domainnewstoptales.top | — | |
domainnewswonderful.com | — | |
domainnewtongame.com | — | |
domainnhaya.fun | — | |
domainnicekeptgame.com | — | |
domainnicelovinggame.com | — | |
domainnicheshu.com | — | |
domainnikejoy.fun | — | |
domainnoodlesd.com | — | |
domainnovelmagic.top | — | |
domainnovelmagic123.top | — | |
domainnovelquesttop.top | — | |
domainnovelwizards.top | — | |
domainnuggetsgame.com | — | |
domainoceantwirl.com | — | |
domainodysseyhorizon.top | — | |
domainofflinequiz.com | — | |
domainoilswaterseparator.icu | — | |
domainomac.fun | — | |
domainonwardgames.top | — | |
domainoop-goal.com | — | |
domainoptifuelknow.com | — | |
domainopyaon.fun | — | |
domainor938.com | — | |
domainorgangame.com | — | |
domainorgangame.top | — | |
domainoriginweb.xyz | — | |
domainovalgames.top | — | |
domainoxhug.fun | — | |
domainoyute.com | — | |
domainpackagegame.com | — | |
domainpart-time-jobs-4794711.zone | — | |
domainpartridgegames.com | — | |
domainpastaties.com | — | |
domainpdflight.com | — | |
domainpeagamer.com | — | |
domainpeaknewsf.com | — | |
domainpeoapp.net | — | |
domainpepach.com | — | |
domainperaic.dev | — | |
domainperksgame.com | — | |
domainpheasantgames.com | — | |
domainpilrimage.com | — | |
domainpinup-yeni-adresi-mobi.com | — | |
domainpinupcasinoguncelgiris.com | — | |
domainpinupyeniadresimobi.com | — | |
domainpixarz.com | — | |
domainpixelquestarena.fun | — | |
domainpixelsprout.lol | — | |
domainplatgamer.com | — | |
domainplayblisshub.com | — | |
domainplaycoxen.pro | — | |
domainplaycubicle.com | — | |
domainplayenemygamer.com | — | |
domainplayfulgamefun.top | — | |
domainplayfulquest12.top | — | |
domainplayhivez.top | — | |
domainplaymasteshr.top | — | |
domainplayport.site | — | |
domainplayshichang.com | — | |
domainplaytopia.pro | — | |
domainplaywarrior.top | — | |
domainplovergames.com | — | |
domainpluslikeplay.com | — | |
domainpluszgames.com | — | |
domainpokerjoy.fun | — | |
domainpoliticxinfo.com | — | |
domainpolywo.com | — | |
domainpopcar.fun | — | |
domainpoping.fun | — | |
domainpoptour.top | — | |
domainposhgames.top | — | |
domainpossfinance.com | — | |
domainpostergamer.com | — | |
domainpovcar.top | — | |
domainpowerplayz.cc | — | |
domainppogame.com | — | |
domainprahaluv.com | — | |
domainpretgame.com | — | |
domainpretydeni.com | — | |
domainprogamemaster.top | — | |
domainprogamerz.top | — | |
domainproofgames.top | — | |
domainpuregygame.com | — | |
domainpurplepeacockbyneera.com | — | |
domainpuzzleplaza.pro | — | |
domainpuzzlid.com | — | |
domainqcggow.com | — | |
domainqsadewnt.com | — | |
domainquadgames.top | — | |
domainquanitumgamer.com | — | |
domainquantrichy.com | — | |
domainquantumcodrise.us | — | |
domainquantumrisehub.top | — | |
domainquickplaypro.top | — | |
domainquickwinning.top | — | |
domainquirk5.com | — | |
domainquirkytests101.top | — | |
domainquizgeek789.top | — | |
domainquizwhiz1010.top | — | |
domainquizzytests101.top | — | |
domainqxcsf.com | — | |
domainradianttop.top | — | |
domainrakegames.com | — | |
domainrapidgamez.com | — | |
domainrapidogame.com | — | |
domainravergames.com | — | |
domainrealestategame.top | — | |
domainrealmnova.com | — | |
domainredbudgames.com | — | |
domainredhotter.com | — | |
domainredtamatofeed.com | — | |
domainresergame.com | — | |
domainreunbot.com | — | |
domainrezzgame.top | — | |
domainrianglo.com | — | |
domainrightgamer.com | — | |
domainrosygameu.com | — | |
domainrpeditnews.com | — | |
domainrubyburst.com | — | |
domainruncel.fun | — | |
domainruoopsharo.com | — | |
domainrustinvest.top | — | |
domainsagafish.top | — | |
domainsamofinance.com | — | |
domainsavoryplanet.top | — | |
domainsciencehub.online | — | |
domainscoutsgamer.com | — | |
domainscreenstouch.com | — | |
domainsecgamer.com | — | |
domainseedsgames.com | — | |
domainsemi-fire.com | — | |
domainserbakuis.com | — | |
domainserenenews.com | — | |
domainsh-mogu.com | — | |
domainshedgamer.com | — | |
domainshenghuijuzhifeng.top | — | |
domainshiftyturn.com | — | |
domainshinygamey.com | — | |
domainshowergamer.com | — | |
domainshrubsgame.com | — | |
domainshrubsgames.com | — | |
domainsiclegame.com | — | |
domainsimulationgame.xyz | — | |
domainsinel.fun | — | |
domainsinkgamer.com | — | |
domainsitegrab.xyz | — | |
domainslissam.com | — | |
domainsloup.top | — | |
domainsmartgamey.com | — | |
domainsnakegamer.com | — | |
domainsoftenergame.com | — | |
domainsolareclipsex.top | — | |
domainsolargames.top | — | |
domainsolitudetop.top | — | |
domainsparkgamet.com | — | |
domainsparkgamey.com | — | |
domainsparkinfoy.com | — | |
domainsparknewsz.com | — | |
domainspeedgamer.top | — | |
domainstainlesssteelmanufacturersusa.icu | — | |
domainstarcrest.top | — | |
domainstarglowingx.top | — | |
domainstarguide.top | — | |
domainstarlightly.top | — | |
domainstarpowerinfo.top | — | |
domainstonegames.top | — | |
domainstorygalaxy555.top | — | |
domainstorysphere.top | — | |
domainstorytellers12.top | — | |
domainstorytime999.top | — | |
domainstovegamer.com | — | |
domainstudiosnews.com | — | |
domainsuccstc.com | — | |
domainsuedae.com | — | |
domainsuitgamer.com | — | |
domainsumokata.com | — | |
domainsunrisegamey.com | — | |
domainsweatergamer.com | — | |
domainswiftaihubx.com | — | |
domainswiftflownews.com | — | |
domainswiftlytips.com | — | |
domainswifttipn.com | — | |
domainsymdoom.com | — | |
domainsyreafsgame.com | — | |
domainsyyyym.com | — | |
domaintailbonetie.com | — | |
domaintailbontie.com | — | |
domaintamotoo.com | — | |
domaintanhcole.com | — | |
domaintarotdelighter.top | — | |
domaintarotfun567.top | — | |
domaintarotfunmania.top | — | |
domaintarotfunzonemagic.top | — | |
domaintarotgateway777.top | — | |
domaintarotguru888.top | — | |
domaintarotinsiders.top | — | |
domaintarotinsight55.top | — | |
domaintarotinsighter.top | — | |
domaintarotinsightful.top | — | |
domaintarotinsightser.top | — | |
domaintarotinspider.top | — | |
domaintarotjoygames.top | — | |
domaintarotmagicfun.top | — | |
domaintarotmastery.top | — | |
domaintarotmysterly.top | — | |
domaintarotmystics9.top | — | |
domaintarotrealm999.top | — | |
domaintarotrealmtop.top | — | |
domaintarottalesfun.top | — | |
domaintarotwonders89.top | — | |
domaintarotzone.top | — | |
domaintastefulstory.top | — | |
domaintastybites2022.top | — | |
domaintastydelites56.top | — | |
domaintastygamer.top | — | |
domaintastygourmetjoy.top | — | |
domaintastynomsdelightly.top | — | |
domaintastyorbits.top | — | |
domaintastytarotfoodv.top | — | |
domaintechbyteinfo.com | — | |
domaintechgane.com | — | |
domaintechgyroinfo.com | — | |
domaintechieinfoo.com | — | |
domaintechiepoint.online | — | |
domaintechinforoom.com | — | |
domaintechybuilders.com | — | |
domaintechygamezone.com | — | |
domaintechyinfz.com | — | |
domainteckx.net | — | |
domaintel-goal.com | — | |
domaintenergame.com | — | |
domaintestgeeklab.top | — | |
domaintestjoywonder.top | — | |
domaintestmaze.top | — | |
domaintestplatform.top | — | |
domaintestyourlimits.top | — | |
domainthegamehub.pro | — | |
domainthegamevista.com | — | |
domainthehighercontent.com | — | |
domaintheshivalya.com | — | |
domainthesnarf.net | — | |
domainthighgame.com | — | |
domainthrivewellnessworld.com | — | |
domaintickgamer.com | — | |
domaintingo.fun | — | |
domaintinux.fun | — | |
domaintofix.fun | — | |
domaintombgame.com | — | |
domaintonglingxw.info | — | |
domaintopnewswave24.top | — | |
domaintopnewswave99.top | — | |
domaintoppedgames.top | — | |
domaintorygame.com | — | |
domaintpfxw.com | — | |
domaintradegame.top | — | |
domaintranquilinfo.com | — | |
domaintraveltodeworld.com | — | |
domaintripletgames.com | — | |
domaintrippher.com | — | |
domaintrisscheng.com | — | |
domaintubeard.com | — | |
domainugame.com | — | |
domainuptogamez.com | — | |
domainuptogane.com | — | |
domainurl-app.com | — | |
domainutritontips.com | — | |
domainvastjoy.fun | — | |
domainvexing.fun | — | |
domainvirtuacorner.com | — | |
domainviviangames.com | — | |
domainvividexsnews.com | — | |
domainvkim.top | — | |
domainvoekgame.com | — | |
domainvoidgames.top | — | |
domainvopfit.com | — | |
domainvopos.fun | — | |
domainvousgame.com | — | |
domainvowt.top | — | |
domainvrshoppinggame.com | — | |
domainvvivireal.com | — | |
domainwackygames.top | — | |
domainwadadeis.com | — | |
domainwaddleplayer.ink | — | |
domainwaistgames.com | — | |
domainwaoshow.com | — | |
domainwardgamer.com | — | |
domainwashgamer.com | — | |
domainwatermarkcamera.com | — | |
domainwaves.ink | — | |
domainweaponscuriosa.com | — | |
domainwidegames.top | — | |
domainwindjoy.fun | — | |
domainwirelessgame.top | — | |
domainwisdomgames.top | — | |
domainwishself.com | — | |
domainwociyu.com | — | |
domainwoffty.fun | — | |
domainwokgamer.com | — | |
domainwonderfulgames.top | — | |
domainwooolgame.com | — | |
domainworkingusa.net | — | |
domainwowenjoys.com | — | |
domainxenicgames.top | — | |
domainxqbdh66.com | — | |
domainxylofy.com | — | |
domainyintao02.com | — | |
domainyongo.fun | — | |
domainyummybooks.top | — | |
domainyummyeats888.top | — | |
domainyuyibld.com | — | |
domainzeldagame.top | — | |
domainzentraxtips.com | — | |
domainzentrixinfo.com | — | |
domainzesttipsz.com | — | |
domainzhidagame.com | — | |
domainzinkgame.top | — | |
domainzinko.top | — | |
domainzippygamez.com | — | |
domainzlon.fun | — | |
domainzontime.com | — | |
domain8083.play.quizzop.com | — | |
domain8085.read.newszop.com | — | |
domain8aa1ba05.rushquiz.com | — | |
domainab.oxhug.fun | — | |
domainab.tingo.fun | — | |
domainab.wishself.com | — | |
domainabs.fun-goal.com | — | |
domainaft.fofopub.fun | — | |
domainaft.lopub.fun | — | |
domainam.fofopub.fun | — | |
domainam.oxhug.fun | — | |
domainam.popcar.fun | — | |
domainam.tingo.fun | — | |
domainanc.fofopub.fun | — | |
domainanc.fun-goal.com | — | |
domainarcade.funforge.site | — | |
domainas.tingo.fun | — | |
domainaug26h.liveingame.com | — | |
domainax.runcel.fun | — | |
domainbg.netplay.fun | — | |
domainbg.tingo.fun | — | |
domainbrand.minigame.vip | — | |
domainbsc.ai-goal.com | — | |
domainc.misffgame.com | — | |
domaincdn.ai-goal.com | — | |
domainde.registrea.com | — | |
domaindes.fun-goal.com | — | |
domaindes.luno.fun | — | |
domaindwz.cocolans.fun | — | |
domaindwz.naxru.top | — | |
domaindwz.opyaon.fun | — | |
domaindwz.popcar.fun | — | |
domaindwz.poping.fun | — | |
domaindwz.povcar.top | — | |
domaindwz.wishself.com | — | |
domaindwz.zinko.top | — | |
domaine06zh.merifall.com | — | |
domainelectricvehiclefans.faberk.com | — | |
domainerp.onceisnotenough.ca | — | |
domainextra.minigame.vip | — | |
domainf.gameleb.com | — | |
domainf.swiftflexa.com | — | |
domainfashion.firenzeire.com | — | |
domainfilm.minigame.vip | — | |
domainfinance.insightivetip.com | — | |
domainfinance.misffgame.com | — | |
domainfinance.phriao.com | — | |
domainfinance.quixoteinfo.com | — | |
domainfood.vibrantews.com | — | |
domainfun.biugames.com | — | |
domaing1.h5game1.com | — | |
domaing1.toolol.top | — | |
domaingame.aialeek.com | — | |
domaingame.bliscanemon.com | — | |
domaingame.boomgamef.com | — | |
domaingame.brighugame.com | — | |
domaingame.cactiapi.com | — | |
domaingame.dromeling.com | — | |
domaingame.echoloot.pro | — | |
domaingame.fernetari.com | — | |
domaingame.hexwin.fun | — | |
domaingame.knighzgame.com | — | |
domaingame.legendgamey.com | — | |
domaingame.mindflexa.com | — | |
domaingame.newsavenuey.com | — | |
domaingame.noclemoon.com | — | |
domaingame.playbuzz.online | — | |
domaingame.returnlitnews.com | — | |
domaingame.rnalaler.com | — | |
domaingame.sereneevoke.com | — | |
domaingame.smartgamey.com | — | |
domaingame.snookershow.com | — | |
domaingame.tuusonit.com | — | |
domaingame.zhengxuitnews.com | — | |
domaingame01.chipandgames.com | — | |
domaingame02.chipandgames.com | — | |
domaingas.sinel.fun | — | |
domainge.opyaon.fun | — | |
domainget.minigame.cool | — | |
domaingfun.ai-goal.com | — | |
domaingoodac.dailynewscome.com | — | |
domaingpdz.jzfreegames.com | — | |
domaingphb.ravergames.com | — | |
domaingym.zingoinfo.com | — | |
domainhd04.gamesgarden.info | — | |
domainhealth.troquerde.com | — | |
domainhhm.lolagamers.com | — | |
domainhot.calfgames.com | — | |
domainhow.tel-goal.com | — | |
domaininsurance.quixoteinfo.com | — | |
domaininvest.fincoin.top | — | |
domainled06.gamesgarden.info | — | |
domainnc.acruy.fun | — | |
domainnc.fofopub.fun | — | |
domainnc.nhaya.fun | — | |
domainnc.sloup.top | — | |
domainnc.tel-goal.com | — | |
domainnews.aimoongames.com | — | |
domainnews.healthute.com | — | |
domainnk.axtun.fun | — | |
domainnk.bluejoy.fun | — | |
domainnk.crazyjoy.fun | — | |
domainnk.destinyjoy.fun | — | |
domainnk.fun-goal.com | — | |
domainnk.luno.fun | — | |
domainnk.poping.fun | — | |
domainnk.povcar.top | — | |
domainnk.sloup.top | — | |
domainnk.tel-goal.com | — | |
domainnk.tingo.fun | — | |
domainnk.tinux.fun | — | |
domainnk.vastjoy.fun | — | |
domainnk.wishself.com | — | |
domainnk.woffty.fun | — | |
domainnp.acruy.fun | — | |
domainnp.tinux.fun | — | |
domainns.ai-goal.com | — | |
domainnszc.rokiread.com | — | |
domainob.povcar.top | — | |
domainob.windjoy.fun | — | |
domainopt.fofopub.fun | — | |
domainph.fofopub.fun | — | |
domainplay.arking.fun | — | |
domainplay.ashgame.top | — | |
domainplay.echoloot.pro | — | |
domainplay.fun-goal.com | — | |
domainplay.funforge.site | — | |
domainplay.h5gameapp.com | — | |
domainplay.hot9game.com | — | |
domainplay.kimgame.com | — | |
domainplay.oxhug.fun | — | |
domainrdm.tinux.fun | — | |
domainrw.axtun.fun | — | |
domainrw.oxhug.fun | — | |
domainrw.tofix.fun | — | |
domainrw.zlon.fun | — | |
domains.povcar.top | — | |
domains1.digifuseinfo.com | — | |
domainsearch.googledouble.top | — | |
domainsokida.games4html5.com | — | |
domainsokida.lopsgame.com | — | |
domainsokida.peelgames.com | — | |
domainss.tinux.fun | — | |
domainstylaxu.trendenclave.com | — | |
domainteun09.gamesgarden.info | — | |
domaintotoro029.jzfreegames.com | — | |
domaintotoro040.jzfreegames.com | — | |
domaintravel.cightingle.com | — | |
domaintravel.cleverinfy.com | — | |
domaintravel.seviotive.com | — | |
domainttq1.liveingame.com | — | |
domaintx.lopub.fun | — | |
domainubt.oxhug.fun | — | |
domainubt.popcar.fun | — | |
domainubt.poping.fun | — | |
domainubt.sloup.top | — | |
domainubt.zinko.top | — | |
domainvogxu.hairsalonparkerco.com | — | |
domainw.axtun.fun | — | |
domainw.sinel.fun | — | |
domainwtg.sinel.fun | — | |
domainwtg.tingo.fun | — | |
domainyc.gamesgoplay.com | — | |
domainyc.h5cloudgame.com | — | |
domainyc.lolagamers.com | — | |
domainym.nhaya.fun | — | |
domainym.runcel.fun | — | |
domainym.tel-goal.com | — | |
domainzc.lolagamers.com | — |
Threat ID: 68434ffe71f4d251b5de3cd6
Added to database: 6/6/2025, 8:30:54 PM
Last enriched: 7/8/2025, 12:14:09 PM
Last updated: 7/12/2025, 11:55:13 AM
Views: 13
Related Threats
Evolving Tactics of SLOW#TEMPEST: A Deep Dive Into Advanced Malware Techniques
MediumAttackers Inject Code into WordPress Theme to Redirect Visitors
MediumPatch, track, repeat
MediumAnalysis of APT-C-55 (Kimsuky) Organization's HappyDoor Backdoor Attack Based on VMP Strong Shell
MediumAtomic macOS Stealer includes a backdoor for persistent access
MediumActions
Updates to AI analysis are available only with a Pro account. Contact root@offseq.com for access.
External Links
Need enhanced features?
Contact root@offseq.com for Pro access with improved analysis and higher rate limits.