A growing number of Android TV boxes are secretly masquerading as smartphones, using their owners’ home broadband connections as proxies for malicious activities, a concerning trend that raises serious security concerns.
These cheap streaming devices, often touted as budget-friendly alternatives to smart TVs and set-top boxes, have become unwitting accomplices in cybercrime. A disturbing discovery by researchers has revealed that some Android TV boxes are being exploited to create an army of hijacked home networks, which can then be leveraged for a wide range of illicit purposes.
The issue arises from the fact that many Android TV boxes are running outdated versions of Android, often with known security vulnerabilities still present. These devices’ ability to masquerade as smartphones is largely down to their implementation of a feature called “Network Location.” This function allows them to use mobile phone network operators’ infrastructure to make outgoing calls and send texts, but in this case, it’s being used to create a covert connection between the TV box and the attacker’s command-and-control server.
The hijacked home networks can then be employed for various malicious activities, including spreading malware, conducting DDoS attacks, or even hosting illicit content. The scope of these operations is vast: researchers have found evidence that some compromised devices are being used to host phishing sites, cryptocurrency mining software, and even child exploitation material.
As the Internet of Things (IoT) continues to grow, so too does the attack surface. With millions of connected devices in use worldwide, it’s becoming increasingly difficult for security teams to keep pace with emerging threats. The problem is further exacerbated by the fact that many IoT devices are often underfunded and lack robust security measures.
The affected users are primarily those who own Android TV boxes from unknown or unverified vendors. Many of these devices have been sold online, with some retailers even unwittingly contributing to the issue by not properly vetting their suppliers. As a result, it’s estimated that thousands of households worldwide may be unknowingly hosting malicious activity on their home networks.
To mitigate this risk, users are advised to check the Android version running on their TV box and ensure it is up-to-date. If the device is no longer receiving security updates from its manufacturer, it should be replaced with a more secure alternative. Additionally, users should exercise caution when purchasing IoT devices online, opting for well-known brands that prioritize security.
In light of this discovery, users are reminded to remain vigilant about their home networks and the devices connected to them. Regularly monitoring network activity, running up-to-date antivirus software, and implementing robust firewalls can go a long way in safeguarding against these types of threats. As the IoT continues to evolve, so too must our approach to securing it – prioritizing device security, education, and awareness will be crucial in preventing these types of malicious activities from spreading further.
Source: The Hacker News — 2026-07-31