
Important information
This post is intended for general information and awareness. Not all customers are affected.
If you have been contacted directly by Sunrise, please follow the instructions provided in that message.
—
More and more devices in our homes are connected to the Internet – for example smart TVs, streaming boxes, digital photo frames or projectors.
These so‑called IoT devices (Internet of Things) offer convenience, but they can also pose security risks.
One currently known type of malicious software in this context is called BadBox.
In this article, we explain in a simple and easy‑to‑understand way what BadBox is, what risks it involves and how you can protect yourself.
—
🔍 What is BadBox?
BadBox is malicious software (malware) that can mainly affect Android‑based IoT devices, such as:
What makes BadBox special
In many known cases, the malware was already present on the device at the time of purchase.
Users therefore did not install anything intentionally.
👉 Important: People affected have generally done nothing wrong.
—
🧠 What can BadBox do in the background?
From the outside, an affected device often appears to work normally. In the background, however, it may:
become part of a remotely controlled network (botnet)
forward or generate Internet traffic
be used for fraudulent activities such as click or advertising abuse
download additional malware
These activities usually happen without the user noticing.
—
❓ How does BadBox get onto a device?
In many known cases:
the malware is installed during manufacturing or before sale
very inexpensive devices from unknown manufacturers are often affected
regular security updates or an official Android / Play Store certification are often missing
—
✅ How can I protect myself? (Prevention)
Even without technical knowledge, there are many things you can do.
🛒 When buying a device
Prefer well‑known brands and manufacturers
Be cautious with very cheap no‑name devices
Be skeptical of promises like “everything unlocked” or “free content”
🔄 After purchase
Update software and firmware regularly
Do not install apps from unofficial app stores or sources
Do not disable security features
🌐 In your home network
Keep your router up to date
Check for unknown devices in your home network
If possible: connect IoT devices to a separate Wi‑Fi network (guest network)
—
🚨 What should I do if I suspect an issue?
Possible signs include:
unusually high data usage
the device becomes very slow or unusually warm
unknown apps or services
warnings from authorities or Internet service providers
In this case, we recommend:
Disconnect the device from the Internet
Do not continue using it
If possible, reset the device to factory settings
If suspicion remains: replace the device
⚠️ Note: With BadBox, a factory reset does not always permanently solve the problem, as the malware may be deeply embedded in the system.
—
🤝 Why are we informing you about this?
It is important to us that you:
Today, cybercrime does not only affect computers or smartphones, but also many everyday devices.
—
✅ In short
BadBox can affect certain Android‑based IoT devices
In many cases, the malware is already present at the time of purchase
Very cheap no‑name devices are particularly affected
Care when buying devices, regular updates and conscious use significantly reduce risks
📌 If you have been contacted directly by Sunrise or are unsure, please contact our Customer Security Team at abuse@sunrise.net.
Our specialists will be happy to help you.
—
❓ Frequently Asked Questions (FAQ) – BadBox & smart devices
Note
These questions and answers are intended for general information and awareness.
Not all customers are affected.
If you have been contacted directly by Sunrise, please follow the instructions received.
—
🔐 What is BadBox in simple terms?
BadBox is malicious software that can be present on certain Internet‑connected devices, such as streaming boxes, smart TVs or other Android‑based devices.
It is often active in the background without being visible.
—
🦠 Is BadBox a virus?
Not in the classic sense.
BadBox is malware that acts more like an invisible co‑user, misusing the device for other purposes – often without obvious effects in daily use.
—
📱 Which devices can be affected?
Mainly:
Very cheap devices from unknown manufacturers are more frequently affected.
—
❓ Did I do anything wrong?
No. Clearly not.
In many known cases, the malware was already on the device when it was purchased.
The cause often lies in the supply chain or with the manufacturer – not with the user.
—
🛒 Are only cheap devices affected?
Not exclusively, but very cheap no‑name devices carry a significantly higher risk.
With well‑known brands that provide regular updates, the risk is much lower.
—
🏪 Are devices from official shops safe?
They are generally safer, but not automatically 100% safe.
Important factors include:
—
⚠️ What can BadBox actually do?
In the background, an affected device may:
This usually happens without the user noticing.
—
🌐 Can my IP address be misused?
In rare cases, Internet traffic may be routed through an affected device, making it appear as if certain activities originate from your own connection.
This is normally not directly visible to the user.
—
🐢 Will my Internet become slower?
It can, but it does not have to.
Unusually high data usage can be an indicator, but not definitive proof.
—
🔍 How can I tell if a device is affected?
Unfortunately, this is difficult. Possible signs include:
the device is very slow or unusually warm
high data usage without explanation
unknown apps or services
warnings from authorities or Internet providers
—
🛡️ Does antivirus software help?
Often not reliably.
BadBox can be deeply embedded in the system and may not be visible to many antivirus apps.
—
🔄 Is a factory reset sufficient?
In many cases, no.
The malware may remain in the system and become active again after the reset.
—
🚨 What should I do if I suspect an infected device?
Disconnect the device from the Internet
Do not continue using it
If possible, contact the manufacturer or perform a reset
If suspicion persists: replace the device
—
☎️ Do I need to inform Sunrise?
If you have been contacted directly by Sunrise or are unsure, please contact our support or the Abuse Team at abuse@sunrise.net.
We will be happy to assist you.
—
🧠 Should I now be afraid of all smart devices?
No.
The vast majority of devices work safely when they are up to date and come from trusted sources.
—
✅ In short
BadBox can affect certain Android‑based IoT devices
The malware is often already present at the time of purchase
Users are generally not at fault
Careful purchasing decisions, updates and conscious use significantly reduce risks
Further information:
- Ibarry
- BSI
- Google
Greetings
Daniele