Discussion
Loading...

Post

  • About
  • Code of conduct
  • Privacy
  • About Bonfire
Julius Schwartzenberg - Юліус
@jschwart@mas.to  ·  activity timestamp 4 hours ago

@briankrebs note that you can run Armbian on some of these. Be sure to look at the Armbian forums for unofficial builds if there's no official build.

  • Copy link
  • Flag this post
  • Block
Token Sane Person
@tokensane@mastodon.me.uk replied  ·  activity timestamp 7 minutes ago

@briankrebs I think the "Overseas Use Only" is because a device for use in China would have to comply with the Great Firewall and not try to connect you to streaming services that are banned in China.

  • Copy link
  • Flag this comment
  • Block
Daniel 黄法官 CyReVolt 🐢
@CyReVolt@mastodon.social replied  ·  activity timestamp 12 minutes ago

@briankrebs As easy as it is to hate on China, let's please recheck. They are behind their firewall that renders anything unusable or at least close to unusable that is connecting from outside to inside and vice versa.
Not that cheap TV boxes are to be expected high quality, that is.

  • Copy link
  • Flag this comment
  • Block
BrianKrebs
@briankrebs@infosec.exchange replied  ·  activity timestamp 7 minutes ago

@CyReVolt Okay. Everyone here is such an expert. Can't wait for next year.

  • Copy link
  • Flag this comment
  • Block
rabbit5959
@rabbit5959@social.vivaldi.net replied  ·  activity timestamp 19 minutes ago

@briankrebs Interestingly enough, you also find that kind of label on some American foods. "For sale only in the United States, overseas territories, and military bases". Surely WE'RE not the botnet.... are we??

  • Copy link
  • Flag this comment
  • Block
Nicola
@CryogenicIce9@mastodon.online replied  ·  activity timestamp 31 minutes ago

@briankrebs You're right, all chinese made TVs should block youtube, all things google, wikipedia, yandex video, twitch and all things amazon by default, just like they have to in mainland china.

  • Copy link
  • Flag this comment
  • Block
Nicola
@CryogenicIce9@mastodon.online replied  ·  activity timestamp 27 minutes ago

@briankrebs Also, a brief list of TV networks that should not be viewable on any chinese made TV:

ABC, ABC (au), CBC, All BBC channels, NBC, HBO, Bloomberg, WION, TIME and so on.

I guess what I'm saying is that this is the stupidest fucking take out of all the stupid takes you've ever had.

  • Copy link
  • Flag this comment
  • Block
Netraven
@Netraven@hear-me.social replied  ·  activity timestamp 39 minutes ago

@briankrebs don't worry, America has been doing the same and releasing software and hardware with backdoors in it to everyone for decades.

  • Copy link
  • Flag this comment
  • Block
doopledi
@doopledi@sauna.social replied  ·  activity timestamp 40 minutes ago

@briankrebs Fairly interesting too that according to "reports" some AndroidTVs have not had a software update in ages. I'm yet to make a fuss about it but...

  • Copy link
  • Flag this comment
  • Block
crazyeddie
@crazyeddie@mastodon.social replied  ·  activity timestamp 1 hour ago

@briankrebs The cited article makes this sound more like the boxes get infected with something through post-purchase install.

The TVs that are packaged for overseas have the software for overseas that includes access to stuff that their own citizens are not allowed to access. The main google app stores and such.

Stuff like CE and FCC marks are for the whole package. Software included.

The botnet is a worry and these things are NOT secure, but this stamp doesn't say anything worrisome for us

  • Copy link
  • Flag this comment
  • Block
x41h
@x41h@infosec.exchange replied  ·  activity timestamp 2 hours ago

@briankrebs yup

  • Copy link
  • Flag this comment
  • Block
Regendans
@regendans@todon.eu replied  ·  activity timestamp 2 hours ago

Page won't load for me. archive.org to the rescue : https://web.archive.org/web/20251221132941/https://blog.xlab.qianxin.com/kimwolf-botnet-en/

奇安信 X 实验室

Kimwolf Exposed: The Massive Android Botnet with 1.8 Million Infected Devices

Background On October 24, 2025, a trusted partner in the security community provided us with a brand-new botnet sample. The most distinctive feature of this sample was its C2 domain, 14emeliaterracewestroxburyma02132[.]su, which at the time ranked 2nd in the Cloudflare Domain Rankings. A week later, it even surpassed Google
  • Copy link
  • Flag this comment
  • Block
Becca
@bweller@mstdn.social replied  ·  activity timestamp 2 hours ago

"Investigations found that the author of Kimwolf shows an almost "obsessive" fixation on the well-known cybersecurity investigative journalist Brian Krebs, leaving easter eggs related to him in multiple samples.

For example, in sample 2078af54891b32ea0b1d1bf08b552fe8, the domain fuckbriankrebs[.]com is embedded in both its udp_dns and mc_enc attack methods, used to generate DNS request payloads."

😂🤣

@briankrebs

  • Copy link
  • Flag this comment
  • Block
Jellal
@jellal@sakurajima.moe replied  ·  activity timestamp 3 hours ago

@briankrebs I looked through the article, but I don't see how China-produced products are related to this botnet. Doesn't the malware focus on Android streaming boxes regardless of where they were produced? As far as I can see, the article didn't link the botnet to China either. (There are genuine questions btw.)

  • Copy link
  • Flag this comment
  • Block
Jackie 🍉🏳️‍⚧️☭
@burnoutqueen@todon.nl replied  ·  activity timestamp 3 hours ago

@briankrebs

telling people to waste perfectly good TV boxes that can run Linux is absolutely the wrong takeaway

  • Copy link
  • Flag this comment
  • Block
BrianKrebs
@briankrebs@infosec.exchange replied  ·  activity timestamp 3 hours ago

@burnoutqueen ok. that's fine. I recognize there are some people who think piracy is a right and anyone saying otherwise is ill-informed, a tech noob, or a fear monger.

  • Copy link
  • Flag this comment
  • Block
Allan Girvan
@agirvan@glasgow.social replied  ·  activity timestamp 3 hours ago

@briankrebs

You should stick to something safe, like an Amazon Firestick.

They're made in...

China!

https://www.accio.com/supplier/amazon-fire-stick-manufacturer

Amazon Fire Stick Manufacturers: Verified Global Suppliers & Custom Solutions

Need reliable Amazon Fire Stick manufacturers? Connect with certified suppliers offering low MOQ, 4K streaming devices, and customization options. Request quotes today!
  • Copy link
  • Flag this comment
  • Block
George E. 🇺🇸♥🇺🇦🇵🇸🏳️‍🌈🏳️‍⚧️
@gme@bofh.social replied  ·  activity timestamp 3 hours ago

@briankrebs@infosec.exchange
I do find it funny that "FOR OVERSEAS ONLY" is written in ENGLISH and not Mandarin. You would think if a product was not designed for the Chinese market, would warn the Chinese that the product is for export only, in Chinese. Most Chinese are not bilingual. LOL.

  • Copy link
  • Flag this comment
  • Block
cake-duke
@oneloop@mastodon.xyz replied  ·  activity timestamp 3 hours ago

@briankrebs Krebs is on mastodon! Awesome! Following.

  • Copy link
  • Flag this comment
  • Block
miki
@miki@dragonscave.space replied  ·  activity timestamp 3 hours ago

@briankrebs How do those devices (along with all the fridges and IOT cameras that make up most botnets) get infected? Aren't most of them behind NAT? I understand "default passwords", but for that to be a problem, there has to be a way for the attacker to connect to a device in the first place, and that is the part I don't get.

  • Copy link
  • Flag this comment
  • Block
BrianKrebs
@briankrebs@infosec.exchange replied  ·  activity timestamp 3 hours ago

@miki this is the subject of my reporting in the New Year. Stay tuned.

  • Copy link
  • Flag this comment
  • Block
Karel 'Clock' K.
@clock@f.cz replied  ·  activity timestamp 3 hours ago

@briankrebs I don't think China is a country. I think it's a stateless territory infested by a criminal communist terrorist organization whose kingpin is Xi Jin Ping.

  • Copy link
  • Flag this comment
  • Block
Fellows
@fellows@cyberplace.social replied  ·  activity timestamp 3 hours ago

@briankrebs I don’t own one but my understanding is that these Android TV boxes are typically used for watching pirated content. I can’t see any company putting heavy efforts into the security of their product when it’s used for this purpose. Whether they’re intended to be a Trojan horse or not, the risk their use brings is too high in my humble opinion and I agree with Brian, they should be binned.

  • Copy link
  • Flag this comment
  • Block
Karel 'Clock' K.
@clock@f.cz replied  ·  activity timestamp 3 hours ago

@briankrebs Evidence that "these things are responsible for building out a botnet that currently has ~2M devices and is growing rapidly"?

  • Copy link
  • Flag this comment
  • Block
BrianKrebs
@briankrebs@infosec.exchange replied  ·  activity timestamp 3 hours ago

@clock are you asking for evidence? Read the story I linked from XLAB.

  • Copy link
  • Flag this comment
  • Block
Clayton O'Neill
@clayton_oneill@mastodon.cloud replied  ·  activity timestamp 4 hours ago

@briankrebs You seem to be implying this violates some chinese security regulations and isn't approved for domestic sale, but the much more likely explanation is that these boxes are banned in China due to state media control concerns: https://www.ibtimes.com/china-cracks-down-set-top-box-market-bans-popular-streaming-apps-2189776

International Business Times

Set-Top Box Crackdown Riles Consumers In China

Chinese consumers are not happy with the change, saying the government's new rules are meant to support cable companies and establishment media.
  • Copy link
  • Flag this comment
  • Block
Julius Schwartzenberg - Юліус
@jschwart@mas.to replied  ·  activity timestamp 4 hours ago

@briankrebs note that you can run Armbian on some of these. Be sure to look at the Armbian forums for unofficial builds if there's no official build.

  • Copy link
  • Flag this comment
  • Block
BrianKrebs
@briankrebs@infosec.exchange replied  ·  activity timestamp 4 hours ago

@jschwart AFAIK, there's no way to use these devices securely.

  • Copy link
  • Flag this comment
  • Block
Julius Schwartzenberg - Юліус
@jschwart@mas.to replied  ·  activity timestamp 4 hours ago

@briankrebs it's not clear to me why replacing the entire software wouldn't make them secure.

It might possibly even work to simply kill the offending applications. I have a very cheap box (was around $25) which became quiet with regards to traffic after I stopped various applications (mainly a torrent one that was there with a preconfigured torrent was establishing a lot of connections).

When I insert an SD card with Armbian, it just boots that instead of Android.

  • Copy link
  • Flag this comment
  • Block
Julius Schwartzenberg - Юліус
@jschwart@mas.to replied  ·  activity timestamp 3 hours ago

@briankrebs the XLAB article mentions the X96Q which matches the model on my box (there are different boxes with that model though).

It also mentions that the culprit is in some so files from a particular apk. This means running Armbian should be fine if you have an affected box:
Working images can be found on the forums: https://forum.armbian.com/search/?q=X96Q

I'll check if my box has those apk/so files when I get an opportunity.

Generally the hardware itself should be fine though, wasteful to just bin it.

  • Copy link
  • Flag this comment
  • Block
Nicolas Guay
@machinaecrire@mstdn.social replied  ·  activity timestamp 4 hours ago

@briankrebs @jschwart How about not hooking it to the Internet and just using it at a display device? (Honest question.)

  • Copy link
  • Flag this comment
  • Block
BrianKrebs
@briankrebs@infosec.exchange replied  ·  activity timestamp 4 hours ago

@machinaecrire @jschwart If I told you a certain brand of Christmas tree lights could burn your house down, would you then pull out all the lights from the strand and use it as an extension cord?

  • Copy link
  • Flag this comment
  • Block
Héliosélène
@helioselene@h4.io replied  ·  activity timestamp 4 hours ago

@briankrebs

It could be the other way around: less spying for foreigners? After all, China spies on its own citizens more than anyone else.

  • Copy link
  • Flag this comment
  • Block
BrianKrebs
@briankrebs@infosec.exchange replied  ·  activity timestamp 4 hours ago

Meant to link to my previous reporting on this topic, which briefly touches on some of the challenges w/ the ubiquity and sheer insecurity-by-design of most of these Android TV/movie streaming devices

https://krebsonsecurity.com/2025/11/is-your-android-tv-streaming-box-part-of-a-botnet/

Is Your Android TV Streaming Box Part of a Botnet?

On the surface, the Superbox media streaming devices for sale at retailers like BestBuy and Walmart may seem like a steal: They offer unlimited access to more than 2,200 pay-per-view and streaming services like Netflix, ESPN and Hulu, all for…
  • Copy link
  • Flag this comment
  • Block
Sterling
@AG100pct@infosec.exchange replied  ·  activity timestamp 3 hours ago

@briankrebs Nice article !

Sorry, no caption provided by author
Sorry, no caption provided by author
Sorry, no caption provided by author
  • Copy link
  • Flag this comment
  • Block
Mike. 🩼🇨🇦
@MikeImBack@disabled.social replied  ·  activity timestamp 4 hours ago

@briankrebs I switched to Roku...I hope thats good. I haven't heard anything about Roku yet

  • Copy link
  • Flag this comment
  • Block
Mans R
@mansr@society.oftrolls.com replied  ·  activity timestamp 38 minutes ago

@MikeImBack @briankrebs Roku reports your usage every few minutes and shows ads, though both can be subverted with DNS blocks.

  • Copy link
  • Flag this comment
  • Block
Sébastien Duquette
@ekse@noc.social replied  ·  activity timestamp 4 hours ago

@briankrebs I think you're reading too much into this one Brian. This is most likely because of the different voltage, the US uses 120v, China uses 240v like Europe.

  • Copy link
  • Flag this comment
  • Block
Neil Craig
@tdp_org@mastodon.social replied  ·  activity timestamp 4 hours ago

@briankrebs Feels weird that they write "overseas use only" in English...seems like Mandarin might be a better choice perhaps? 🤣🤷🏼‍♂️

  • Copy link
  • Flag this comment
  • Block
AI6YR Ben
@ai6yr@m.ai6yr.org replied  ·  activity timestamp 4 hours ago

@briankrebs 😱

  • Copy link
  • Flag this comment
  • Block
Log in

Bonfire community

This is a bonfire demo instance for testing purposes

btfree.social: About · Code of conduct · Privacy ·
Bonfire community · 1.0.0 no JS en
Automatic federation enabled
  • Explore
  • About
  • Public Groups
  • Code of Conduct
Home
Login