A $30 Android TV box confirmed pre-infected at the factory. Researcher AyaanB bought a device named in FBI and CISA advisories, isolated it from all network access, identified serial port test pads, connected a low-voltage serial adapter, broke into the bootloader, and dumped the full MMC filesystem over TFTP. The malware is signed as a system application, lives on the system partition, holds SELinux exceptions granting shell privileges, and runs multiple launch scripts to survive partial removal. It matches the Vo1d botnet, hooks into Android's process spawning layer to subvert every app at launch, runs hidden browser windows for ad-click fraud, bids in real-time ad auctions, and provides a root-level backdoor for operators to push additional tools. The methodology of the extraction, done entirely offline, is worth reading on its own.
Two other stories demand attention. Researcher Lina registered an expired domain for five Euros and accidentally inherited control of the e164.arpa DNS delegation for Saint Helena, Diego Garcia, and Ascension Island. That obscure early-2000s standard maps phone numbers directly to DNS records for SIP and VOIP routing. Six months after shelving the project, Lina checked the logs and found hundreds of thousands of attempted call resolutions, including traffic destined for military bases. Transparent call hijacking was possible for the cost of a coffee. The domains were eventually transferred to the UK National Cyber Security Center. Separately, AliExpress was caught playing silent audio waveforms at zero volume in the browser background, measuring CPU, audio hardware, and driver-level variances to fingerprint visitors across sessions without cookies. WebGL, WebRTC, and screen resolution data were collected alongside the audio signal. Firefox patched this attack vector three years ago. Most other browsers remain exposed.
The full writeup also covers Signal's contact discovery protocol and arrests tied to the TeamPCP group. The Signal section is technically dense: it details how Signal uses Intel SGX enclaves and oblivious RAM to run contact lookups without exposing your contact list to Signal's servers, and where the attack surface still exists. If you follow secure messaging infrastructure or hardware enclave security, that section alone justifies reading the original.
[READ ORIGINAL →]