• Welcome to ASR. There are many reviews of audio hardware and expert members to help answer your questions. Click here to have your audio equipment measured for free!

Cheap Android IPTV Boxes - Security Warning

JSmith

Master Contributor
Joined
Feb 8, 2021
Messages
7,646
Likes
22,124
Location
Algol Perseus
Android IPTV boxes, that are cheap and promise the world, are a massive security risk...

They inject malware directly into the firmware.

The malware turns your IPTV box into a secret "node". The hackers sell your home internet bandwidth to other criminals who route malicious traffic through your IP address to mask their identity.

The malware actively attempts to move laterally through home networks, attempting to alter router DNS settings and intercept data from other connected devices.

The malicious/fake IPTV apps are dropping banking trojans like massiv and perseus... to continuously take screenshots, log keystrokes, and steal banking info.
Amazon sell these on their platform and the usual like Ali and eBay... they should be pulled from their platforms, beware.


JSmith
 
Only marginally related but Linus tech tips made a video recently on why smart tvs are so cheap (basically because they sell your data) while they review a very uncommon non smart current TV. Worth watching.
 
None of this is exactly news though - they've been doing it for years. That applies both to malware pre-loaded on streaming boxes and sometimes phones, and trojan apps for Android in general. Cheap android devices rarely get software updates, and often ship with old Android versions, so they're likely to be vulnerable within a few months even if they don't come pre-installed with malware.
 
Oh yes IPTV, the dungeons of pirated PayTV streams.. people should avoid these apps, boxes or Kodi-mods. But then they are addicted to football etc.

It's easy to make a smart TV a dumb TV. Don't give wifi, don't plug it in (after occasional firmware update). Unfortunately they have become massive ad/malware hosts.

As for TV boxes in general, there are also many serious brands with quality devices and solid software. What they ship as standard (AOSP etc.) might not be to everyone's taste (what they bundle/pre-install), but they are not malware outlets.

How to find a proper TV/media/audio box: visit the CoreElec site (Kodi on Linux for these boxes). Look which brands (not chips) they support and work with. Those are serious ones.
 
Interesting. Begs the question : how to differentiate/know what is risky. I've been using Minix and Zidoo boxes for many years. Gave up Kodi a long time ago however. No indication of any malware as yet. But how exactly do you tell?
 
Interesting. Begs the question : how to differentiate/know what is risky. I've been using Minix and Zidoo boxes for many years. Gave up Kodi a long time ago however. No indication of any malware as yet. But how exactly do you tell?
Minix is fine at least for the two models I own. You can tell exactly by using the supplied firmware and monitoring the network activity of the box.

Kodi is good on a Linux kernel because it overcomes all those Android limits. It's also on GitHub with source code, possibly subject to automated and custom checks.

On the other end some cheap Ali box with old Android for $39 - that's not clean I assume.
 
Kodi is good on a Linux kernel because it overcomes all those Android limits. It's also on GitHub with source code, possibly subject to automated and custom checks.
The plugins people want to use to get to the dodgy media sources are another thing entirely - binary only and capable of accessing the credentials you provide to the legit plugins, among other things.
 
TV disconnected from internet and AppleTV seems to continue to be the way to go.
 
The plugins people want to use to get to the dodgy media sources are another thing entirely - binary only and capable of accessing the credentials you provide to the legit plugins, among other things.
If someone wants to use these payTV things, the minimum requirement is to put the whole box with only that software into a guest network, as provided by many home routers. At least protect the rest of the household from being attacked by malware.

Apps/plugins that participate in a botnet - that's what it is really - are another level. Sadly there are usually no consequences for the end user, but people have to understand that they are giving ressources to criminals.

But customers of pirated payTV have been targeted by the authorities. Whenever they bust a vendor and get hold of a nice customer database with payment info.
 
I'd rather pay extra for a normal certified box from a well-known brand than have to deal with someone hacking my connection or trying to access other devices at home. It's also quite annoying that the average user often doesn't even notice that something is happening. Do any of you check if they have normal security updates when buying such boxes?
 
Back
Top Bottom