Skip to content

Podcast

172- SuperBox

Darknet Diaries

Source ↗ ← All highlights
  • Discovery At Dad’s House Led To Packet Captures
    • Deadass discovered Superbox at her father’s house and quarantined it on a separate network to watch its traffic.
    • She learned packet capture basics, used a Hack5 packet capture device, and observed the box beaconing to Tencent and slowing the home network. Transcript: Deadass Without giving away too much, he’s one of the senior people at his oil and gas company. Jack Rhysider Okay. And so you go to visit him and… Deadass Yeah. So my dad is very, I don’t want to say nonchalant, but he’s like, he’s chill, right? Like he’s a very chill kind of person. So for him to be excited, I was like, oh, well, what are you excited about? Like you’re very deadpan. Like you don’t get excited. Jack Rhysider Her dad was excited about all the channels and shows and movies that he could get on his TV now. He’s like, look at this. I got hundreds of movies, full series of all the latest TV shows, thousands of channels, sports, even pay-per wrestling matches. You like wrestling, deadass. You would love this thing. And he’s telling me about it. He’s like, yeah, it’s just 300 bucks. It just works. It’s called the Superbox. Deadass And immediately I’m like, okay, this already sounds weird, but keep going. So I ask, like, well, how does it work? And he says, oh, it just works. That’s not what I asked you. I asked you, how does it work? And so my younger sister was also studying cybersecurity. She comes in and she says, oh yeah, the network’s been really slow at the house ever since those boxes came home. So that was kind of my final red flag to be like, I’m going to get one just to see what it’s doing. Jack Rhysider Boxes? Deadass Yeah, boxes. What? Multiple, more than three. Why does he have so many? Because they’re convenient. That’s how they get you. Oh, for each TV? Yeah, for each TV. Okay. How did he get it? Somebody at his job told him he needed to get one really, really bad, so he got one. Jack Rhysider She takes one home to look at it. She’s not a researcher, so she’s not sure where to start. She knows enough that she should quarantine this thing, though, so she put it in a separate network so it doesn’t learn about her home network or try to bother any of her other devices, And she puts it behind a firewall. Then she starts Googling where to start. Deadass It was the weirdest question I’ve ever asked out loud. How do I get PCAPs at the house? Because I had to figure out how to get packet captures off the thing. And I’m like, (Time 0:08:03)
  • Superbox Uses ARP Flooding To Impersonate Devices
    • The Superbox performed aggressive ARP scanning that could knock devices offline then impersonate them by taking their IP/MAC.
    • It repeatedly flooded local IPs, caused IP reservation failures, then changed its MAC/IP to pose as the victim device. Transcript: Jack Rhysider A SCADA vulnerability? This makes no sense. SCADA is the control systems used in large scale industrial settings. Think pumps, valves, conveyor belts, elevators, railway switches, this is where SCADA systems live. Why in the world is this box that’s here to deliver TV and movies attempting to trigger a SCADA exploit on Deadass’ network? This is very concerning. So she continues to look at the traffic this thing is sending, and she notices it’s communicating hard with all the other devices on her local network. Typically, a streaming box will not care about what else is on your local network and only want to go out to the internet and get the content so that it can show it to you on your TV. But this box was super busy feeling around to see what else is in her network. Specifically, it starts arping out to any device in the same network as it. So basically, arp is when a device is like, hey, are there any computers on this network that have the IP 192.168 or whatever. And if there is a device that has that IP, it’ll respond. It’ll say, yeah, that’s me. You want to chat? Here’s my MAC address. And then it gives the MAC address. So this super box was arping out to every IP in Deadass’ network. Deadass I would say it was almost more of like an ARP DOS because it was arping at things so hard that they would like freak out and like lose their IP address reservation. Yeah. Jack Rhysider Really? Deadass Yeah. They were just so chatty. And that was also something weird to me because normal devices, like they’re chatty, but they’re not chatty like that. Right. So it’s this noisy thing on a network. It’s ARP and everything. It’s sniffing around. (Time 0:11:45)
  • Influencer And Reseller Network Drove Grassroots Adoption
    • Superbox distribution used influencer marketing and reseller networks to normalize and scale sales.
    • Small YouTube/TikTok creators were paid commissions (e.g., 50% per sale) to promote boxes, creating grassroots adoption. Transcript: Deadass As I start kind of looking around, I go into YouTube and I’m like, okay, Superbox. And so I see a bunch of different influencers. They’re not like Alinus Tech Tips or some of these other bigger folks that have a huge following on YouTube. These are folks with sometimes like 800 followers, sometimes 50, sometimes, you know, 50K. One guy had like pictures of like motorcycles and like his wife and like pictures of food. And then just a hard right turn and he’s now talking about super boxes. I saw one kid who was like talking about like speakers and then suddenly the super box. So I’m like, that’s really weird. So obviously they had to be paying them and it took me a while to figure this out. But I went way back to like a seven year old, like super box video. And this one influencer was like, yeah, they contacted me and they’re offering me 50% of the proceeds of every device that I sell. Jack Rhysider If I talk about this. Oh, so there’s super bucks influencers out there? People paid to spread this thing? Gosh, this makes it a lot harder to control and stop this. If they’re being sold by random people just trying to make a few extra bucks, it’s almost like they have an army of marketers and salespeople. Deadass They start appearing in weird places. I start seeing it on TikTok. They’re on Facebook Marketplace. So I start getting even more suspicious because I’m like, this has to be a whisper campaign because I’m not seeing it like, I’m not watching cable television and there’s like an ad for The Superbox. And if that ever happens, like I’m gonna just move out of the country at that point. But I haven’t seen that yet. But what I have been seeing is, oh, check out the Superbox. Here’s YouTube shorts about the Superbox. Check out my TikTok. Get it off my store. So it’s spreading. (Time 0:16:58)
  • Infected Homes Create A High-Bandwidth Attack Surface
    • Thousands of infected home devices become large-scale bandwidth and proxy resources, valuable for botnets and residential proxy services.
    • Distributed high-speed home internet gives attackers massive aggregated upload capacity for DDoS and data exfiltration. Transcript: Deadass They’ll just keep going. And then when you factor in the residential proxy stuff, that’s a lot of bandwidth. Jack Rhysider Oh, I see. If thousands of these are in homes across America and those homes all have high-speed internet, that means these boxes have quite a lot of bandwidth at their fingertips. (Time 0:21:00)
  • Outdated Android And Root Access Reveal Hidden Firmware
    • The devices run outdated Android builds (circa 2021), include TeamViewer and exposed ADB, and grant root shells easily.
    • Deadass dumped firmware, found missing partitions, multi-zipped app stores, and root access via ADB SU on multiple boxes. Transcript: Deadass And not Android TV, just Android. I looked at the Android information and it was a patch from 2021. Jack Rhysider Okay, so three-year operating system. At that point, yeah. Deadass And it’s on purpose because this was one of the ones that had a lot of holes in it. When we think about like, you know, not great Android patches that came out, 2021 was kind of a strange year for that. And so I’m looking at that and I’m like, okay, that’s super, super weird. I keep digging in. I’m looking at the box. I’m like, let’s look through the apps. There’s TeamViewer on it. Right. TeamViewer. Jack Rhysider Okay. So TeamViewer is a way to remotely manage a computer. It allows you to connect to that thing and control it as if you’re sitting right in front of it. So with TeamViewer installed on it, that means that whoever is behind this has a dashboard at their fingertips of all the super boxes out there with TeamViewer running. And with one click, they could just jump right into any of them. That’s horrible. Holy cow. The idea that someone is inside your home looking around at your network and you have no idea. No, no, no, no, no. I do not want this. Burn it with fire. Watching Reddit and stuff like that, people are like, is this thing too good to be true? Deadass And so there was an account on Reddit that was created about, at that time, about four years ago, which lines up with like kind of the initial timeline of everything we were seeing with This starting about 2019, 2020. And that account did not post a single thing for four years. And then it pops up just to say, I’ve had the super box for forever. I get NFL, MLB, you know, Sunday ticket. Like this is the best thing ever. Like everyone should get one. And then it never posted again. So they’re of course nudging it and trying to like, you know, prop it up in places. I’m like, so this is, again, it’s spreading. People are talking about it, but like, I still have not heard a thing about it in the security community. So I decided to do a talk on it initially. And that was my first ever like technical talk at a hacker con. I was scared to even get up there. Jack Rhysider So she gave the talk at a B-Sides event and the crowd was stunned with her findings. Her talk was so scary. I think everyone after the talk called home to see if their parents had bought one of these or installed anything like that. Which reminds me, I need to call my dad to see if he has one. Let me take a quick ad break real quick, but stay with us because everything got way more serious after she gave that talk. This episode is sponsored by ExaForce. If you’re a startup, all you want to worry about is growth. But with growth comes an attack surface that scales as fast as you do. What you need is a transparent security platform that adapts to your speed and maturity levels. ExaForce was created to handle the complete security operation workflow, detect, triage, investigate, and respond. Exabots autonomously manage every eliminating gaps between alert and action that slow down traditional security operations. Pre-built integrations and detections for AWS, Azure, and GCP, and SaaS applications from GitHub to Slack and more protect you from the modern attack surface which most traditional Themes overlook. Plus, ExaForce shows the reasoning behind every automated decision, making it easy to audit, tune detection rules, and understand what is going on in your environment. If you want AI that grows with you, then check out ExaForce at exaForce.com/darknet dash diaries. That’s ExaForce spelled E-X ExaForce.com/darknet dash diaries. Okay, my dad says he does not have one, but he says the guy at the gym has one, and he keeps inviting him over to come watch shows. Okay, so after that talk, what happened next? Deadass How can I put this without sounding crazy? Our government was very, very interested in knowing more. I can put it to you that way. Jack Rhysider Yeah, word got out, and an investigation was opened up, and they brought her in to learn more. If this is another nation trying to plant boxes in family homes across America with malicious intent, then the Department of Defense was interested in knowing more. But the thing was, because this was now an active investigation, it meant Deadass had to be quiet about this. So she wasn’t allowed to talk publicly about it. But it didn’t stop her from researching it further and talking privately about it. So for years, she continued to research it and gave talks. But every one of those talks had to be no cameras, no recording, no photos, in order to keep this hush-hush. And it’s been driving me crazy since I’ve been attending her talks for years. And I think it’s such a good story to get out to you. But she’s never been allowed to be interviewed for it. And that’s why I’m so happy to finally, finally, finally get this interview to tell you her story. But as it turns out, this wasn’t the first time we’ve seen bad boxes. Deadass Human security and Google and all those guys have kind of done the stuff on the first Badbox. And they were sourced for a lot of the stuff on the second Badbox. But we basically discovered that this thing was part of what’s now referred to as the Badbox botnet. Jack Rhysider Badbox botnet. So we’ve been referring to it as Superbox this whole time. Yeah. Where’s Badbox come from? Deadass Badbox comes from the fact that there are just other Android streaming devices, and they’re actually a lot cheaper. And this was actually an anomaly that I noticed when I was looking at the Super Box. They’re anywhere from $30 to maybe $100 at most. And so again, cheap devices, they’re kind of everywhere. They can get them out there pretty quickly. And so a lot of those made sense, already infected. You know, the behavior looked the same once I started kind of like providing information and stuff. And so we all came to the determination that it should just be, it’s still Badbox, but it’s Badbox 2.0, even though we’d shut down the first Badbox. And so, yeah, it’s for any Android, basically, device that’s like got malware or is beaconing out to interesting places, etc. But the Superbox, my focus on it is because it’s $300. And the rest of them are like $30. So why is this one $300? Jack Rhysider So she gave the authorities all the information that she discovered about this. Deadass I provided network traffic, some logs, just things so that they could get an idea of what they were looking at. And I just kind of took it from there. So… Jack Rhysider Okay. And then for your own, you didn’t stop with your own research. Oh, no. Deadass I was like, we’re not even, we haven’t even scratched the surface. I know. You know, we’re still like, at that point, I was just like, there’s still more. Like, I know there’s still more because there were still so many unanswered questions. Like, okay, I get why it’s beaconing. I get that it’s talking to this IP. But like, again, why? Why? So I keep digging. I just keep digging (Time 0:21:30)
  • Explain Risk In Terms Your Family Cares About
    • Warn high-risk family members by tying the risk to things they care about, like retirement funds and company credentials.
    • Tell them compromised boxes can monitor logins and expose bank or work credentials to attackers. Transcript: Deadass Well, so what was interesting, I think what got through to my dad was when I said, hey, like, if something goes wrong with this, and you know, you’re in a pretty high position at your company, Like, I mean, people are reporting their bank accounts getting hacked. Like, do you care about your money? Do you care about your retirement? Like, again, they’re looking at your credentials. They’re monitoring the network. They’re going to see when you’re logging into your bank and they’re going to see when you’re doing things that we might all consider sensitive. And if you don’t want that to now become a negative or get (Time 0:35:38)
  • Retail Presence Creates False Sense Of Legitimacy
    • Consumers place implicit trust in big retailers; seeing Superbox on Best Buy/Walmart reduced perceived risk despite third-party marketplace origins.
    • That implied trust let resellers and shady listings normalize a malicious product. Transcript: Deadass And so we don’t have a culture of understanding, again, like scams and stuff like we we lose billions of dollars every year to pig butchering fishing all kinds of get rich quick schemes Like everybody wants to make a buck or everybody thinks that you know oh i’m gonna i’m no longer going to be a temporarily embarrassed millionaire like i’m gonna be a millionaire now Jack Rhysider Or i get to watch tv and i don’t see what the problem is yeah i want to i was at first i was going to push back and say well you know, we assume that the stuff we buy has already been vetted and Secure and all that stuff. Or else it wouldn’t be in the store because the store should have some sort of a responsibility. Deadass There’s implied trust when you go to like Best Buy, right? Like there’s a reason I’m not going to go like stand out here on the corner and say like, hey, does anyone have like an iPhone 17 I can just buy real quick? Like I’m going to go to Apple. I’m going to go directly to Best Buy. And so again, as consumers, especially in the United States, like you said, we go to Best Buy, we assume that what we’re getting is okay. (Time 0:41:45)
  • Publicity Triggered Phishing And A Short DDoS
    • After Krebs’ article gained attention, Deadass received targeted phishing attempts via ProtonMail and LinkedIn asking for her TCP dumps and research.
    • She ignored requests, then experienced a 15-minute DDoS that disrupted her home streaming. Transcript: Deadass So the Krebs article comes out and then I get phished, or at least someone tried to phish me. Because when Mr. Krebs published that article, another IoT researcher got a super box and started finding some cool stuff. And there was a posting of the store itself, like the repo they were using was just kind of out there. When it started to get bigger on YouTube, because of Matt Brown’s work, all of the sudden, the store is not there. It’s not you can’t find the repo anymore. Then I get this email saying, hey, do you have like, you know, the app store dumps? Do you have some TCP dump? And I’m like, first of all, it’s a very personal question. Like, you don’t just, you know, start off asking for people’s TCP dump logs. Like, come on. But I’m like, holy crap. And it’s, of course, coming from a ProtonMail. They said they were a computer science student, but they’re not emailing me from an academic email. And they emailed me at my academic email where I adjunct that I don’t put out anywhere. And I was like, how the hell did you get this? Number one. Number two, wow. Like that was a hard nudge trying to kind of sniff around and see what was going on. So of course I didn’t answer. I was just like, nope. (Time 0:57:18)
  • Botnet Operators Repurpose Vulnerable Streaming Boxes
    • Superbox-like devices were co-opted by KimWolf botnet operators who exploited their vulnerabilities to launch record DDoS attacks.
    • The botnet infected millions of devices and repurposed vulnerable streaming boxes into DDoS nodes. Transcript: Jack Rhysider So this brings us into January of 2026. And around then we saw the largest botnet DDoS attack ever. It was the Kim Wolf botnet. And it was launching attacks at 31 terabits per second. It basically had control of 2 million devices and could tell them all to send traffic to a specific IP on the internet, which would basically flood any computer with so much traffic that It would knock it offline. And you think the super boxes were part of that botnet? They were confirmed as part of that botnet. Here’s the thing. From my understanding, it wasn’t the makers of Superbox who were involved at all in this botnet. These things shipped with a really old version of Android and are loaded with all kinds of remote access features like TeamViewer, Netcat, and stuff. So the person behind the KimWolf botnet simply found how vulnerable these Superboxes were and spread their botnet onto a ton of them. So now this guy Dort, who’s the one who made the Kim Wolf botnet, controls the super boxes. I mean, if I wasn’t already extremely concerned about who’s in these super boxes listening, now there’s Dort in there too, and who knows what he’s doing with these things, turning them Into weapons, I guess. (Time 1:00:30)
  • Portable Infected Boxes Turn Public Networks Hostile
    • Bringing a Superbox into workplaces, cafes, or hotels infects shared networks and can probe other users’ devices instantly.
    • Deadass described cases of remote employees and coffee shops exposing customers and corporate VPNs to scanning boxes. Transcript: Jack Rhysider Or it’s brought to a hotel to watch TV on the go. Or maybe the coffee shop owner installed one so they could play shows on the TVs in the shop. And now when you get on the Wi-Fi in that shop, suddenly you’re on the same network as a computer that’s probing and scanning you and attacking you. This is why I never use Wi-Fi in a coffee shop or a public place. I just picture it riddled with these diseased, infected boxes that are desperately trying to get access to my machine the moment it connects. I bring my own Wi-Fi hotspot with me everywhere I go, so I only trust my own network. Deadass The funniest thing I think that has happened so far was being out at a pho restaurant. And, you know, I’m looking around because someone had just told me they were at a pho restaurant and saw three of them in there. So now I like go into places that I’m like looking and making sure there’s not like a super box behind the TV and stuff like that. Because even if it’s not doing anything else, just the fact that like anything you connect to it, it wants to know about it and it’s going to start poking at it to me is scary. Like if I connect my phone, like, and what, what made me upset about this whole situation with my dad is like, I went over there and didn’t know he had these and had connected like my work Computer at the time and like my phone and stuff to the home network. Cause I was visiting for a couple of days and I’m like, you have these things in the house. These have been plugged in the whole time. Like you, what? And so it exposes all of us in a lot of ways that we may not want to be exposed. And, you know, I’m not doing anything shady, but like, I want my privacy. (Time 1:10:23)
  • Quarantine Unknown Devices And Reimage When Compromised
    • Practice basic security hygiene: use VPNs, re-image compromised machines, and isolate unknown IoT on guest networks or keep devices off networks.
    • Deadass re-imaged systems, uses VPNs, and keeps suspect devices quarantined to limit exposure. Transcript: Deadass Because I think for a lot of us that have been doing this for a while, there’s always going to be places where we’re just like, I don’t just, I just don’t care that much. Cause we already, we’re already in it so much all the time, but I spent some time kind of reflecting on, you know, I was out traveling. Um, and I think I got popped with something cause my phone was acting crazy and all this other stuff. So I blew away everything in the house, re-imaged everything. Everything’s fine now, but I’m like, I’m just going to take some extra steps just to make sure. Because I usually, you know, I always have VPNs on and stuff like that, but, you know, a VPN can only do so much if somebody’s really interested in what you’ve got going on on the other side Of that. (Time 1:12:03)
  • Technical Malware And MLM Tactics Enabled Scale
    • The campaign combined technical malware with MLM-style economics and fake regulatory paperwork to scale and evade oversight.
    • Deadass found fake certificates, QQ-signed import paperwork, and multi-tier reseller incentives that enforced seller compliance. Transcript: Jack Rhysider And where do you land on this? Deadass Okay. So the whole picture is somebody, and I’m going to be vague on purpose because I am still working to get the full picture of the somebody. Somebody is basically getting influencers, of course, to Shillies. There’s an entire distribution network of distributors and resellers. So they’re getting folks in their neighborhoods and in their communities and all these places to sell these boxes to friends, family, everybody, as much as they can, which again, already Weird. They’ve already infiltrated all the big box stores. So again, it’s now looks like this normal everyday has been around for nine years consumer product. We still, of course, have the whole issue with them targeting people directly in oil and gas, which that’s still, to me, I’m like, this got mailed to you at your house, friend? Like, are you going to move? Like, I just, you know, I’m worried for you. And then we still, of course, just have the endless problem of like, there’s no like legitimate, like regulatory tracking on it. They’re dark. There’s no FCC IDs. Like you can’t find really any information on these things. The one that we did find information on, you know, when you’re importing something and it’s coming from overseas, you have to sign off on it and say that like, you know, it’s everything’s Correct. (Time 1:13:18)