What's New: Streaming-Box Devices, Bugs and Takedowns

This is a running log, not a feed of new articles. Each entry is one line and points to the page that owns the full fact, where it is kept up to date. Last verified: October 2026.

Last reviewed: October 2026 Reading time: 4 minutes

How to read this page: one line per event, newest first, each pointing to the page that owns the detail. When something new lands, it updates the owning page and adds a line here. No new article per event, by design.

2026

  • September 2026: Further research described the residential-proxy channel being used to push new malware onto already-compromised boxes. Detail: proxy and botnet basics.
  • September 2026: Lab guidance reiterated that a factory reset and network segmentation alone are not enough for a device with a persistent proxy channel. Detail: check and fix.
  • May 2026: Independent lab research confirmed the phone-home behavior and the network-interference tools in the firmware. Detail: SuperBox and vSeeBox.
  • February 2026: A firmware backdoor affecting new devices was documented, in the same malware family. Detail: proxy and botnet basics.

2025

  • December 2025: A DDoS botnet of about 1.8 million Android devices was documented. Detail: proxy and botnet basics.
  • November 2025: Network-research findings on the risky boxes were reported, including the exposed remote-access door. Detail: SuperBox and vSeeBox.
  • July 2025: A major platform sued unnamed operators over a large TV-box botnet. Detail: proxy and botnet basics.
  • June 2025: The FBI published a public warning and a list of warning signs for infected home devices. Detail: check and fix.

2024

  • December 2024: A national cyber agency disrupted part of an earlier TV-box botnet's control infrastructure. Detail: proxy and botnet basics.
  • July 2024: A court held resellers of these boxes liable. Detail: legality and piracy.

Sources we checked

Found an error? Report it: we log and correct material mistakes.