Hacked - BADBOX
Episode Date: February 2, 2024You can find all kinds of great deals on Android streaming TV boxes online. But sometimes something else comes in the box along with it. Our conversation with Lindsay Kaye - Vice President of Threat I...ntelligence at Human, and part of the security team that discovered that somewhere along the supply chain something else was getting installed into all kinds of Android devices. Learn more about your ad choices. Visit podcastchoices.com/adchoices
Transcript
Discussion (0)
Back in 2019, this story broke about these Android phones.
Since 2016, Google had been trying to root out what is now this very famous family of malware called Triata.
Triata compromised Android devices and mostly used them for a bunch of ad fraud stuff.
It would compromise the device and secretly direct a bunch of traffic from the phone to a bunch of sites
where the fraudulent traffic would be served real ads and the hackers would make money.
And Google had been in this back and forth trying to root triata out.
They were going after insecurity updates.
They locked down the Google Play Store a lot more.
They're kind of just playing defense.
And a few years in, in 2019, Google releases this kind of press release, almost a white paper,
basically about how they had figured out this new attack vector that hackers had been using to get Triata onto the devices,
something that until then had kind of managed to get around all of their new defenses.
And it was no novel, because it wasn't a bad app someone could install or really anything to do with the user.
It had to do with the manufacturer.
The malware was coming pre-installed.
Somewhere along the supply chain, at one of the many vendors and manufacturers and OEMs and sub-venders,
who all had some small part in making the larger phone.
Someone was installing this stuff.
So the phones show up pre-hacked.
Google goes after that.
They change how over-air updates and power cycling works.
they get tighter app controls, play protected, certified Android devices become the norm in North America.
And for a while, it looks like they mostly got it.
On phones.
So I would say that criminals are always enterprising and financially motivated ones are always going to learn to make, or figure out some way to make money.
A while ago, this is an aside, I had a conversation with a friend about piracy.
And we did the thing where you add up how much you pay on streaming services.
Well, how much I pay.
He does a lot of piracy, that's the point.
Some people like streaming sites for piracy.
Some people just torrent on a thing-by-thing basis.
And some people use media servers,
an app like Plex or Cody running on either a PC
or any kind of an Android streaming device
within like plug-in or otherwise access to a big server somewhere
full of stolen stuff.
My friend was one such person.
And after our interview this episode, I texted him.
Hey, what's the thing you use for your whole home theater piracy rig?
Like, what's the box itself?
And he told me the name.
And I said, I have some links for you.
And they are bad news.
So you're probably familiar, but one area in which humans specializes in is ad fraud.
At the end of last year, some security researchers on the Sotori team at Human
noticed this weird traffic?
Our team actually started researching on some anomalous traffic signals that we were observing
because we really want to understand what could be causing them.
And as a result, identified several related apps that seemed to be causing them.
And they traced the traffic back and realized a lot of it was connecting to this weird domain,
where they then found some openly available research to talk.
talking about a T95 set top box that the researchers saw also connected to that domain.
So that was pretty interesting.
And they figured out it had to do with Triata.
The malware Google had spent years trying to root out of Android and largely had from every
Play Protect certified Android device, which is to say basically any phone or tablet you
can buy from a store in a mall in North America or Europe.
but not every Android device you can buy.
Because if right now I were to go over to a large online retailer
and type in Android TV box like the kind my buddy uses,
well, those are a totally different story.
You have heard a couple quotes from our guest this episode,
Lindsay Kay, Vice President of Threat Intelligence at Human.
She is on the team that pulled on this threat.
and found that it led to a giant crazy scheme to break into the hardware manufacturing supply chain,
to find some point along that line where they could pre-install this stuff.
They called it bad box.
And the giant ad fraud scheme it empowers, that deluge of ad monetized fraudulent traffic,
they named that peach pit.
So Scott and I called up the Sotori team to find out what exactly,
happened, how they busted it, and where it's all going next. Badbox, Peach Pit, and how hardware hackers
are infiltrating supply chains here on hacked. Lindsay, thank you so much for sitting down to talk with us about
this. Sure. Thank you so much for having me. I want to start at what would have been the beginning of this
for you and your team. What initially caught your team's attention? How did someone first come across
the devices that were compromised by this?
So you're probably familiar, but one area in which humans specializes in is ad fraud.
So we see various signals related to invalid traffic that might suggest ad fraud's taking
place.
So as a result, as part of an investigation in November 2022, our team actually started researching
on some anomalous traffic signals that we were observing because we really want to understand
what could be causing them.
And as a result, identified several related apps that seemed to be causing them.
So in kind of our initial research, we suspected that the possible source of this invalid traffic was Android TV boxes, but really kind of needed to keep digging.
So from there, one thing that we noticed is that these apps were connecting to a domain, flyermoby.com, which then we continued to dig into, sort of pivot on, look for, you know, any open source intelligence or other sorts of apps or technology that was reaching out to it, and found some openly available research talking about a T-90.
set top box that the researchers saw also connected to that domain.
So that was pretty interesting.
So what we wanted to do is we acquired a T95 device and then as a result,
confirm this research's findings that, oh my God, this T95 device is compromised out of the box
like they were talking about, and then corroborated our suspicions about this flyer
and Moby domain.
So at this point, now we had kind of two big pieces.
So first, that invalid traffic that we'd first identified using our signals,
and we call that eventually Peach Pit.
And then that separate but related operation
with the implanted devices called Bad Box.
So those involved those Android TV boxes
that were infected by this malware known as Triata out of the box.
And from there, what we did was we continued our research
and identified additional devices containing this backdoor.
And at this kind of the end of the research
in right now, our estimate is that over 200 different device models
may include it.
Wow.
Okay, so we have three different things at play here.
We have the malware this was infected with Triada.
What you've labeled Peach Pit, which sounds like this anomalous ad fraud type traffic.
And then we have the boxes themselves.
I want to start with the boxes because that's what made this really fascinating to me was this idea of I order something on the internet and it gets shipped to me preloaded with this malware.
Tell me a bit about the T95.
Where can you buy these devices?
Can you describe how they were being sold and distributed to customers?
Let's zoom in on the box itself.
So devices like the T95 and some of the other ones that we determined did have bad box on them are available widely.
So you think about any sort of online retailers or any sort of brick and mortar stores.
And our team is internationally located.
So there's a wide variety of places that you could buy them.
So pretty much almost anywhere.
And then the interesting thing is that these are all, so,
among the T95 and the other ones that we looked at.
These are off-brand, Android-based, mobile and connected TV devices.
So not just the T-95, but several others.
And, you know, popular online retailers and resale sites.
So pretty much a bunch that you can make.
I love that you're not naming it, but I think we all know who you're talking.
But they're popular.
There are many.
They're very easily accessible to, you know, you and I as average consumers,
if we want to kind of go out and buy any sort of off-brand Android device, very easy to access.
I got a question.
In some of your documentation and blogging about this, you guys talked about iOS traffic coming from Peach Pit.
Is this malware existing on Apple TVs as well?
Is that what that's indicative of?
So I want to kind of be very clear about the difference between Bad Box and Peach Pit.
So Bad Box is that device that's infected with the Triata Backdoor malware.
We only ever saw that on Android devices.
So no iOS devices were involved with that.
So that was the Android mobile, CTV, Android off-brand devices.
And then none of them were Google Play Protect.
So that kind of gives you some idea of what I'm talking about there.
For iOS, we only saw Peach Pit on that.
So those were all applications that were available in the app.
So I believe it was 16 at that point where you can just like as a user,
you go and you download them voluntarily.
So kind of the difference between Bad Box and Peach Pit is Bad Box, you're an unwitting consumer who ends up with his backdoor malware on your device.
For the iOS apps, they might promise to be some game or some other kind of interesting utility that you as a user have to actively download.
Does that help?
Yeah, that helps greatly.
For sure.
So we have two different kind of pools of victims here, both of which are funneling traffic into this Peach Pit ad fraud system.
Yeah, so on the majority of the bad box devices, so those off-brand Android devices, we did see the Peach Pit module downloaded.
So kind of to give you some background here, once you boot up your newly acquired, let's say, CTV box, you put it on your network, the backdoor of the Triata component will reach out to a command and control server and then download some variety of modules.
So the ad fraud module is what we call Peach Pit.
So now you've kind of two sets of devices, those Android devices that have bad box that has unwittingly downloaded that Peach Pit module, and then you have, you know, Android and iOS devices that users are voluntarily going to the store and downloading these apps there.
So the Peach Pit traffic that we're seeing could come from either set of those devices, some from the ones that came through Triata, and then others that users were able to download from the app stores themselves.
So once you're infected with these modules, either because you downloaded them from an app store yourself, or you bought a product that came pre-shipped with them, take me through Peach Pit itself.
This module is in your system.
What is it doing?
What was the goal?
What were the outcomes?
So Peach Pit is, if you're familiar with ad fraud, what it does is it has some sort of hidden advertisements, any sort of spoofed wood, pravick, and malvertising.
So really what this means is that somebody wants to make money.
by either saying that they're showing advertisements
and then not actually showing them
or pretending that an ad is shown to a user
and not actually doing it.
You might see things in other cases
where they have a bunch of ads stacked on top of each other.
So really what they're trying to do is say,
yes, I'm showing these ads,
and then be able to sort of make money sort of on the back end.
And the one thing about the ones that are app-based,
if you delete that app off of your phone,
so your iOS or Android phone, it's gone.
And then no more ad fraud is occurring from that device.
But you probably aren't even aware if you have one of those bad box devices
that pull down that module in the background that this is even happening.
So you're using your Android's ETV device,
you're kind of just off and marry,
and it's conducting that ad fraud in the background.
And unfortunately, there is not a simple and easy,
way like deleting an app to kind of get rid of that. So unfortunately, for a lot of those devices,
you do actually have to discard them. We spoke with the team over at human a while ago about
ad fraud, just trying to get a lay of the land and a basic understanding of like what it was,
how it worked, how it made the crazy volumes of money that it does make for the people that
perpetrate it. I'm struck by it seems like kind of an escalation to be shipping hardware products
to people. This isn't just a question of a dodgy website you go to. This is like, no, you're actually
getting into like a hardware supply chain just in order to redirect ad fraud, like traffic towards
ad fraud. Could you talk to us a little bit about why the scale of ad fraud would justify doing
that? Because it seems like a really, really big undertaking to serve some fake ads to some fake eyeballs.
Of course. So one thing I want to be clear about is that the actors who conducted Peach Pit are
distinct from the bad box set actors. So however those devices are being supply chained,
you know, whether at the manufacturer or point of sale or kind of between there somewhere,
those individuals aren't necessarily the same people as the peach pit individuals. They are likely
working together in some way because obviously if you think about it, if you're developing
that peach pit module and then you need to have it, you know, this backdoor reach out and then
pull it down. There has to be some kind of interface there, but it's based on some of the fact that
we saw other types of modules associated with Bad Box. So there's the residential proxy,
and then there's the one-time password module that suggests that, you know, maybe they are
monetizing that in some entirely different way. So I wouldn't consider necessarily Bad Box developed
entirely to make this ad fraud peach pit stuff happen. It's possible that, you know, these
other modules are able to be monetized in another way as well to really kind of incentivize that,
you know, backdooring of that hardware. Got it. So the bad box operation is getting malware
onto these devices before they ship to you. Peach Pit is simply one way you could use that
compromise. Correct. So can you take me through maybe some of the other stuff? You gesture towards
them just there in your last answer. But what other things are these compromised bad box devices being
used for. So we didn't dig into that necessarily as much in some of that public reporting.
We continue to kind of figure out sort of how the operation is changing these days as well.
But residential proxies. So if you're not familiar with residential proxies, sometimes threat
actors will actually use those because they want to obscure some of where their traffic is coming
from. So things like account takeover and if you're a credential stuffing attacks, you know,
then the IPs look like they're coming from somebody's home IP rather than from something
that might be a little bit more worrisome if a company were to see it. So this residential
proxy module that we observed, what happened was the user's bad box device, so off-brand Android
mobile and CTV devices only, were actually, we saw them become nodes in a residential proxy.
So you can think about it. It's like, okay.
Well, now what would somebody necessarily do with this traffic?
So it's something that a threat actor put if they wanted to sell access to other threat actors
to buy some of that residential proxy network access to do whatever it is that they want.
But that is definitely another way of kind of thinking about it as well.
The one-time password, we're not entirely clear necessarily why they would use that.
We had some theories, but I don't believe it's as strong as kind of looking at some of that residential
proxy.
The other big prong of this, okay, I think I have a sense of bad box versus peach pit,
not just in terms of like how it affects people, but, you know, that these are two separate
groups.
The last part of it is triata, the malware.
How should we understand that and all this?
So triata is that malware that makes these bad boxes, bad boxes.
They are the back doors.
And in short, it's been around since 2016.
So a very long time and then the best way to understand that is this triata malware at some time between
what's manufactured and given to retailers is installed on those devices and then as a result different
sort of models are pulled down into it. So basically just kind of a simple backdoor, it only
affects those non-Global play protect and her devices and it's something that a user wouldn't have a
any understanding of just by looking at the device. So we do at human have some idea of how to,
you know, obviously detect if a bad box is a bad box or not, but, you know, to the naked eye,
it looks perfectly fine to anybody who's purchasing it. And there are certainly are ways to
make sure that you're not, or make sure that you have less of a chance of buying a bad box.
But it's something that wouldn't be apparent if you just acquire it versus those apps that
conduct peach pit where if you have just the peach pit, you have to actively go out and
download that app as a user from the app store. You'd be fully aware that you were doing that.
Got it.
Apple's iTunes store and the app store is kind of known for rigorous controls, Q&A on the
developer side. So like if you submit something with bad code in it or something that doesn't
meet Apple standards, they have a high rejection rate. I'm just wondering, you know,
how they manage.
or if you know how they managed to get this malware into a bunch of iOS apps?
So I truly don't.
But we have continued to work with Apple to make sure that we've reported these apps and had them removed and explained to them how it works so that in the future it's something that, you know, if they want to pursue as well, that's great.
I know Google also has a very similar, similarly rigorous process now.
I think it's less, it's a little bit newer than maybe apples, but we've worked heavily with them.
We continue to work with them as needed.
Gotcha.
So somewhere along the supply chain, Triata gets installed in these devices.
That's the vector for all this bad box stuff, which is bigger than just Peach Pit, but also includes the Peach Pit ad fraud network that you disrupted.
I want to talk about that disruption in a minute, but the part of this that I was really compelled by has to do with that moment in the supply chain.
right, where that malware gets put onto these devices.
I don't think I saw this specifically in the report.
I'm kind of curious, where do you think that's happening?
As a layperson, I'm buying something.
At what point does it get compromised by this malware?
So truthfully, that's something that we don't have any visibility into, right?
So we, like, you know, anybody else, buy these devices, often, you know, a variety of these retailers.
So we have no clue based on kind of when it would.
is first manufactured up until then, sort of what's happened to it.
So obviously that's something that people might speculate about, but we have no insight.
So unclear.
I mean, that brings up another interesting moment.
What is it like buying these things?
Like you're kind of going fishing for a pretty bad fish, weird metaphor.
But you're having this thing shipped to you.
Like, are you, how do you silo it?
How do you make sure that it doesn't mess anything up?
Like, take me through the process of hitting by on one of these things, getting it in the mail,
and cracking it open.
Sure.
So it's much like buying pretty much anything, if you think about it.
So like I said, it's widely available, variety of retailers.
You know, you go, you buy the device.
Obviously, because of the signals that we're able to see associated with page bit,
that gave us some indication of like which devices should we target.
So give you a sense of like, oh, okay, maybe I'll buy one of these, one of those, one of the other things.
Just kind of get a wide variety of devices.
obviously my team has so many different devices now at their homes related to this and some of the rest of our work.
But it's worth noting that if you're receiving this device, you have to kind of assume that it's infected until you're sure that it is not.
Just kind of a great way to treat all sort of malware like that.
And as I mentioned, we have a technique based on a lot of what we've talked about in the report for determining it something is a bad box.
So kind of looking for some of those IOCs to figure out, you know, is this a bad box or not?
But always treat it like it is a bad box.
You know, use good malware hygiene when you're doing your research, things like that.
I guess I didn't really consider the possibility that once you've confirmed to a reasonable level of satisfaction that there's nothing wrong with this device, you could just take it home and use it as a TV set top box.
But like the courage of plugging that in.
Well, I would suggest, you know, obviously sticking to a lot of the device, the advice that we've talked about.
Sure.
Those Google Play protect devices and, you know, buying only name brands and, you know, just being kind of really careful about what it is.
So, you know, I would never test the device say, oh, it doesn't have a bad box on it.
I'm good to go entirely.
So just kind of treating research devices like their research devices.
Sure.
Fair enough.
Yeah, before you take it home and log into Netflix with it and just.
just hope, hope everything's okay.
So can you give me a bit of a sense of the scale of this operation?
Number of devices affected, the geographical spread.
How big is this thing we're talking about here right now?
So at the peak, what we noticed is that there were an average of $4 billion requests a day
to that peach pit kind of ad fraud operation, right?
So $4 million requests a day at its peak.
And what we saw is a total of 280,000 devices infected.
So that was 121,000 Android devices and 159,000 iOS devices.
So across 227 countries and territories.
So when I mentioned that, you know, this was definitely a global operation
and it was affected, you know, a wide variety of individuals.
Like, that's entirely true.
Think about the last time you heard a breach story on this show.
It always starts the same way.
Someone somewhere saw something too late.
An alert buried, a signal missed, an SOC that just couldn't keep up.
Arctic Wolf set out to solve that problem by rebuilding security operations from the ground up for a world where attackers are already using AI.
They created the Aurora Super Intelligence Platform, a fully agentic system powered by the swarm of experts.
Instead of single-purpose bots or lucky-guess LLMs, this swarm is full of deterministic agents that handle whole entire workforce.
Humans stay in the loop and on the loop to validate the critical decisions and keep everything trustworthy,
and all of this is just off running on their secure operations graph.
A constantly updating intelligence engine fueled by more than 9 trillion telemetry events every week
and over a decade of real-world incident response.
The system reasons on real signals and real context not synthetic training data.
And the result is the new Aurora agent SOC.
It's the first SCC that is agent led by design.
You get agents that coordinate, agents that investigate, agents that respond at,
machine speed and hundreds more that automate the repetitive work that normally buries human
analysts. Arctic Wolf didn't try and bolt AI onto an old model. They rebuilt the model entirely.
What makes it even more effective is how it works with Arctic Wolf's concierge experience.
The team brings customer-specific context directly into the platform so every AI-driven decision
reflects your environment instead of generic assumptions. The automation frees your concierge security
team to focus on higher value strategy and proactive risk reductions while the agents
handle the grind. If you want to see what trustworthy, production-ready AI and security
operations actually looks like, go to arcticwolf.com slash hacked.
Never feel like cyber threats are evolving faster than anyone can keep up?
Last year, 2025 was nothing short of a record-breaking year for major breaches,
from sophisticated ransomware operators to AI-enabled attacks to turn defenses on their
head. Organizations around the world saw headlines they never expected and cybersecurity teams
were tested like never before, but here's the thing. These incidents aren't just news headlines.
They're learning opportunities. And that's why Arctic Wolf is hosting a live webinar on February
5th, diving to the most impactful breaches of 2025. Their field CTO and security leaders are
going to unpack not just what happened, but why these attacks succeeded. And most importantly,
what businesses can do to fortify their defenses for it's too late. You're going to walk away with
real insights in how threat actors are evolving, how defenders are responding, and what strategies
can help you stay ahead of the next big breach. It's not fearmongering. It's practical, actionable,
intelligence from experts in the trenches. Register now at arcticwolf.com slash hacked.
You talked a little bit about the residential proxies and some of the other stuff happening
on the bad box devices, but from like a victim perspective, what kind of impacted these
vulnerabilities have on their privacy and security, the people that were using these devices.
Do you have a sense of that?
So, if you think about it, any device that necessarily like this has a backdoor to it,
if somebody is able to discover it or how it works or subvert it in some way,
obviously that opens up users to risks.
We didn't identify that happening in any of the devices that we saw.
But, you know, if you have to think about it, there are certainly ways that people
considerate a lot of these different types of devices.
I think kind of at the more, you know, topic level, right, though,
I think this report impacted consumers who now are starting to think about, like, their security, right?
Because it's like, you know, you would go on internet, you'd buy a device, you would plug it in.
But now I think this report really made people start to kind of think twice about that.
It's like, what am I really buying?
What am I really bringing into my home?
You know, these are things that certainly can happen.
And I think this report opened some people's eyes to, oh, my God, this is something that can happen.
Like, I had no idea.
and then these devices can be just in my house.
So maybe I should really kind of be a more cognizant consumer of, you know,
what it is that I am spending my money on and bringing in my home.
As a brief aside, when I was reading about this story,
prepping for this call, I was doing kind of a little bit of an accounting
of everything that was connected to the Wi-Fi network in my apartment.
Because, boy, do you get paranoid when you read about this thing for long enough?
And I just had this moment of like this.
giant exhale because a couple years ago, my partner and I bought an automated cat feeder.
And we were humming and hauling trying to decide between the internet connected one and the
dumb version. And I'm, I just want to let everyone know because I know you're all worried that
we bought the dumb one that doesn't connect to the Wi-Fi network off of Amazon, off of a very
popular online retailer. So for now, I think I'm good. But see, it really does make you think.
And it's like, oh, my God, let me go check what's on my, on my network. So I think that you're not the
only one probably. Well, I'm glad to hear that. In terms of, okay, let's get to the good part,
the disruption, the takedown, how did you go about that? What measures were taken? How did you start
going about trying to disrupt part of this operation once you really had a full understanding of what
it was that you were looking at? Sure. So after we identified where a lot of this traffic was coming
from and had a good idea of what traffic signals were to block, so we started the investigation
November. So in December 2020, we actually blocked the invalid traffic generated by the Peach Pit
Apps. So this is kind of that first step of the takedown. Kind of on the additional side there,
as part of that Peach Pit ad fraud investigation, we actually identified those 20 apps in Google's
Play Store and 17 apps and Apple's App Store that were part of this operation and then started working
closely with Google and Apple teams to make sure that the apps were reported and started getting taken
down. So explaining a threat to them, you know, what is the impact, and then work with them
to make sure that they are taken down. And know after, continuing to monitor and work with
our partners to see what Peach Pit was doing, making sure that volume was reduced as we expected
it to, and remain mitigated if we needed to. We could have certainly kind of continued and
modified and stuff like that. So that's kind of on the Peach Pit side. So that's that take down
there, where we really have a lot of that same visibility and sort of power to do that. But if you look at
bad box, human doesn't have that same ability to really directly disrupt it in the same way.
Because if you think about, you know, how is this amount we're getting on, you know, how is it
affected? How could it even come off? If it cannot. So it's interesting to kind of see, you know,
outside of what human can control, you know, if you look at what's been happening since,
it seems like the report that we actually put out was effectively part of that disruption there for
the bad box stuff. So looking kind of at some of the stuff that the industry is doing. So I don't know
if you saw, but in November 2023, the EFF actually wrote a letter to the FDC that urged them to
take action in stopping a resale of these infected Android television set-top boxes and mobile devices.
So they named, I believe, all-inter and rock chip devices by different retailers. So the letter
actually cited humans report on bad box and gave a brief technical explanation based on the report.
and they talked a little bit about the consequences of reseller inaction and the brist of consumers.
So while it's human is not directly taking down bad box, it's like steps like these really start
to make people think.
And, you know, when it comes to it, getting that sort of letter to the FTC is really powerful.
So we also saw actually an Australian retailer pull out all the T95 boxes that they were selling.
So immediately based on our research.
So it's like these kinds of small steps that are being taken.
by retailers and by kind of government and things like that in the U.S. is actually really interesting.
And I don't know if you had a chance to look on any of the online retailers.
You can see that some of the devices are actually being renamed,
so not kind of the names that they were being sold under before,
which suggests that maybe their device sales could have been affected in some way based on the publication of our report,
or maybe they read our report even.
We can't say for sure exactly how it happened,
what happened, but that's definitely interesting. And, you know, we continue to work with industry
partners. So many different channels, because we want to address this kind of threat. So not the same
direct kind of impact to do the take down that we did with the peach bit, but we do continue to work
to this day. I'm struck by how whoever manufactures the T95 is not necessarily a participant
in any of these. I'm struck by the fact that that device is still for sale on a popular online
retailer. How would you suggest people think about purchasing these devices? Let's maybe go there.
How would you imagine someone would stay safe, knowing that any number of these internet set top
boxes on popular online retailers might be compromised? Sure. So I would recommend if you have a choice,
make sure that you kind of recognize the benefit of sticking to those well-known, recognized
brands of hardware devices wherever possible. So for example, like those bad box devices were not
Play Protect Certified. So that's something that, you know, if you have a choice between buying
an off brand non-certified device versus one that is, does kind of have that certification,
which, you know, says that it is safe. I would go with the safe one, right? So I'm sure there's kind of
some cost to benefit to buying those off-brand devices. But like we've kind of seen, we really don't
have insight just by looking into it, like looking at it physically, like if something could be
wrong with it. You know, Triata is just one example of potential malware. So I would say trying to,
you know, buy only devices that sort of meet that threshold and that name brand kind of
recognition, if possible. Aside from just set top boxes, that's obviously the focus of the bad
boxes and stuff. Jordan and I were recently discussing. I bought a new washing machine, had to buy a new
washing machine's a better way to put it. And it's got essentially a small computer and it connects
to my IoT network, the whole nine. Now that there's like a small computer in everything,
you know, do you see the potential for the same kind of attack trajectory to kind of play out
through so many other internet of things devices? Or is it like, do you see the set top boxes as
being a bit of a unique appliance that allows for this? So I believe other researchers for at least
the past several years, have talked about some of the vulnerabilities and dangers of some IOT devices.
So this is not necessarily a new thing that has emerged. Like I'd mentioned, Triata's been around
since 2016. So ever since then, it's like, okay, well, there are obviously more opportunities
for threat actors if they want to do something to a device. Do I know specifically how and which
and whether it'll be an ad fraud thing? No. But if you kind of, you know, Google, you know,
IoT malware, you can see other reports of people who have identified kind of similar,
but different threats related to some of those smart devices.
I guess just to wrap up, you know, this is our second conversation with y'all about ad fraud.
The first one was lay at the land and, you know, it was mostly about web traffic.
This is a sort of novel version of that with this hardware compromise.
In terms of ad fraud, where do you think this goes next?
What is the escalation?
what, if you had to speculate on like the new attack vector of 2024, like where do you think
this is all going?
So I would say that criminals are always enterprising and financially motivated ones are always
going to learn to make or figure out some way to make money.
So like I mentioned, things like Bad Box and this peach pit were just kind of one example
of ad fraud and then supply chain devices.
But if you look, it's some of the techniques that they have are still working.
So what we do often see is, you know, they might have one operation.
Let's say researchers, we figured out, we write about it, we get rid of it.
They'll just modify it a little bit to kind of work to evade detections.
So I think we'll see more kind of around things like those residential proxies and kind of that monetization of some of this data.
We'll probably see them, you know, slightly tweak some of that the ways that they do add fraud.
because really it is just kind of like the rest of cybersecurity,
almost a cat and mouse game, right?
So you're a criminal, you make your malware.
Researchers find it and they stop it.
You tweak it slightly.
They find it again.
So it just kind of keeps going like that.
You know, they will have their operation.
Let's say it gets taken down, disband, rebrand, and keep going.
And you'll be there to keep playing the cat and mouse game.
Yes, absolutely.
Did you guys have the ability to,
did you ever trace back or geographically kind of identify
where a lot of this traffic or the origin of this malware had come from?
So in terms of where the infected devices were
or in terms of where Peach Pit and Bad Box were?
In terms of where Peach Pit and Bad Box were.
Okay.
So currently we believe that the Bad Box operation was based out of China.
was possibly one or many Chinese manufacturers being involved in building those devices.
In terms of the threat actors conducting peach pit, we identify three different entities.
Can't really say exactly where they are.
But we did continue to work with law enforcement to make sure that they were aware
and could kind of deal with them appropriately.
That's interesting because it kind of suggests that whoever those manufacturers were in China
that we're compromising with Triata were almost like a vendor is the wrong word, but had a business
relationship with whoever was operating Peach Pit. It's almost like you're sending up a satellite
and we want to put something on it. It's like you're sending out a compromise device. We'd like to
include something with it. So like I mentioned, the actors conducting Peach Pit are distinct from
the bad box set actors. Are they likely working together in some way? Probably. But truthfully, we don't
actually know where any of those entities are located besides, you know, what we believe and what
we think. And we don't have any kind of, you know, clear, irrefutable evidence of how exactly
they are connected. Fascinating. Lindsay, thank you so much for sitting down with us to talk about
this. It was a very interesting one. Awesome. Thank you so much for having me. I really enjoyed it.
Yeah, thanks for coming on.
