The obvious benefit of having a streaming stick, TV box or player running the Android operating system is that Android is open, allowing users to install apps that are not available in official media app stores. There are some interesting new ways to stream entertainment using any Android audio-visual device, not to mention all kinds of customization and web development. There are a variety of Android TV boxes available at various price points. You may choose alternatives with similar functions but cheaper prices. However, you also have to consider digital security issues. The ease of installing homebrew software that comes with the Android TV framework is not only a convenience, but it’s also a double-edged sword.

Think twice before buying a cheap Android TV box
At the end of 2023, a cybersecurity company called Human Security published a report onDetailed report on low-end Android streaming TV box investigation. This follows research conducted earlier this year by cybersecurity expert Daniel Milisic, who discovered a suite of malware on a cheap Android player he purchased out of the box.

According to Human Security at the timeSurvey results shared with WIRED, approximately 200 different models of low-end Android TV boxes were infected with some form of malware that was likely added to the device’s firmware at some point between manufacturing and sale. All of these low-end products typically cost less than $50 and are sold online and in stores. These devices have names made up of seemingly random letters and numbers, like MXQ or T95Z, and are either completely unbranded or labeled with obscure, weird-sounding company names that no one has ever heard of. It’s also worth noting that Human Security also discovered a similar security flaw on an off-brand Android tablet, in addition to various low-end Android boxes, suggesting these shady practices are more common than you might think.

Since this study was published, Google has worked hard to remove and disable infected TV and company-related apps. Unfortunately, malware-infected hardware is a proverbial hydra, and when one head is cut off, others will take its place. Although security research units have revealed many problems, there are still many bad actors trying to find vulnerabilities.
These devices could open backdoors into your account and network
Two main types of malware were found on the devices studied by Human Security: Badbox and Peachpit. Both can be secretly inserted into the firmware of your Android TV box and start wreaking havoc on your digital life.
A Badbox is actually a global network of infected devices, linked together by specific malware. When you use a Badbox-infected device to quietly connect to that network, bad actors can use the network and accounts you’re connected to for a variety of nefarious purposes, including accessing home networks sold as secret proxies, using your network to create fake accounts for services like Gmail and WhatsApp, and remotely installing code onto other devices in your home that are connected to the network. Basically, it turns your home network into a cog in a huge evil machine.

Peachpit operates similarly to Badbox, although its explicit purpose is advertising fraud. Peachpit exploits your network and low-quality, compromised Android apps to request large ad views, spoofing your device credentials to display ads for a quick profit. Human Security speculates that advertising revenue generated by Peachpit may be funding Badbox’s operations, although this is only a theory.

These are just two examples of what can happen when using a low-end Android TV box, and no matter how tempting the ultra-cheap tech may be, remember to always stick with trusted, well-known brands, at least for the sake of brand credibility.
Source: KOCPC Chinese