{"id":37255,"date":"2026-01-26T12:39:22","date_gmt":"2026-01-26T12:39:22","guid":{"rendered":"http:\/\/localhost\/?p=37255"},"modified":"2026-01-26T12:39:22","modified_gmt":"2026-01-26T12:39:22","slug":"who-operates-the-badbox-20-botnet","status":"publish","type":"post","link":"https:\/\/zero.redgem.net\/?p=37255","title":{"rendered":"Who Operates the Badbox 2.0 Botnet?_KREBS:8657B84E0B5E90694CA65B56A6236AC9"},"content":{"rendered":"<p>{&#8220;lastseen&#8221;:&#8221;2026-01-26T18:05:09&#8243;,&#8221;description&#8221;:&#8221;The cybercriminals in control of **Kimwolf** &#8212; a disruptive botnet that has infected more than 2 million devices &#8212; recently shared a screenshot indicating they&#8217;d compromised the control panel for **Badbox 2.0** , a vast China-based botnet powered by malicious software that comes pre-installed on many Android TV streaming boxes. Both the FBI and Google say they are hunting for the people behind Badbox 2.0, and thanks to bragging by the Kimwolf botmasters we may now have a much clearer idea about that.\\n\\nOur first story of 2026, The Kimwolf Botnet is Stalking Your Local Network, detailed the unique and highly invasive methods Kimwolf uses to spread. The story warned that the vast majority of Kimwolf infected systems were unofficial Android TV boxes that are typically marketed as a way to watch unlimited (pirated) movie and TV streaming services for a one-time fee.\\n\\nOur January 8 story, Who Benefitted from the Aisuru and Kimwolf Botnets?, cited multiple sources saying the current administrators of Kimwolf went by the nicknames \\&#8221;**Dort** \\&#8221; and \\&#8221;**Snow**.\\&#8221; Earlier this month, a close former associate of Dort and Snow shared what they said was a screenshot the Kimwolf botmasters had taken while logged in to the Badbox 2.0 botnet control panel.\\n\\nThat screenshot, a portion of which is shown below, shows seven authorized users of the control panel, including one that doesn&#8217;t quite match the others: According to my source, the account \\&#8221;**ABCD** \\&#8221; (the one that is logged in and listed in the top right of the screenshot) belongs to Dort, who somehow figured out how to add their email address as a valid user of the Badbox 2.0 botnet.\\n\\n![](https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2026\/01\/badboxpanel.png)\\n\\nThe control panel for the Badbox 2.0 botnet lists seven authorized users and their email addresses. Click to enlarge.\\n\\nBadbox has a storied history that well predates Kimwolf&#8217;s rise in October 2025. In July 2025, Google filed a \u201cJohn Doe\u201d lawsuit (PDF) against 25 unidentified defendants accused of operating Badbox 2.0, which Google described as a botnet of over ten million unsanctioned Android streaming devices engaged in advertising fraud. Google said Badbox 2.0, in addition to compromising multiple types of devices prior to purchase, also can infect devices by requiring the download of malicious apps from unofficial marketplaces.\\n\\nGoogle\u2019s lawsuit came on the heels of a June 2025 advisory from the **Federal Bureau of Investigation** (FBI), which warned that cyber criminals were gaining unauthorized access to home networks by either configuring the products with malware prior to the user\u2019s purchase, or infecting the device as it downloads required applications that contain backdoors \u2014 usually during the set-up process.\\n\\nThe FBI said Badbox 2.0 was discovered after the original Badbox campaign was disrupted in 2024. The original Badbox was identified in 2023, and primarily consisted of Android operating system devices (TV boxes) that were compromised with backdoor malware prior to purchase.\\n\\nKrebsOnSecurity was initially skeptical of the claim that the Kimwolf botmasters had hacked the Badbox 2.0 botnet. That is, until we began digging into the history of the qq.com email addresses in the screenshot above.\\n\\n## CATHEAD\\n\\nAn online search for the address **34557257@qq.com** (pictured in the screenshot above as the user \\&#8221;**Chen** \\&#8221;) shows it is listed as a point of contact for a number of China-based technology companies, including:\\n\\n-**Beijing Hong Dake Wang Science \\u0026 Technology Co Ltd.**  \\n-**Beijing Hengchuang Vision Mobile Media Technology Co. Ltd.**  \\n-**Moxin Beijing Science and Technology Co. Ltd.**\\n\\nThe website for Beijing Hong Dake Wang Science is**asmeisvip[.]net** , a domain that was flagged in a March 2025 report by **HUMAN Security** as one of several dozen sites tied to the distribution and management of the Badbox 2.0 botnet. Ditto for **moyix[.]com** , a domain associated with Beijing Hengchuang Vision Mobile.\\n\\nA search at the breach tracking service **Constella Intelligence** finds 34557257@qq.com at one point used the password \\&#8221;**cdh76111**.\\&#8221; Pivoting on that password in Constella shows it is known to have been used by just two other email accounts: **daihaic@gmail.com** and **cathead@gmail.com**.\\n\\nConstella found cathead@gmail.com registered an account at jd.com (China&#8217;s largest online retailer) in 2021 under the name \\&#8221;\u9648\u4ee3\u6d77,\\&#8221; which translates to \\&#8221;**Chen Daihai**.\\&#8221; According to **DomainTools.com** , the name Chen Daihai is present in the original registration records (2008) for moyix[.]com, along with the email address **cathead@astrolink[.]cn**.\\n\\nIncidentally, astrolink[.]cn also is among the Badbox 2.0 domains identified in HUMAN Security&#8217;s 2025 report. DomainTools finds cathead@astrolink[.]cn was used to register more than a dozen domains, including **vmud[.]net** , yet another Badbox 2.0 domain tagged by HUMAN Security.\\n\\n## XAVIER\\n\\nA cached copy of astrolink[.]cn preserved at archive.org shows the website belongs to a mobile app development company whose full name is **Beijing Astrolink Wireless Digital Technology Co. Ltd**. The archived website reveals a \\&#8221;Contact Us\\&#8221; page that lists a Chen Daihai as part of the company&#8217;s technology department. The other person featured on that contact page is **Zhu Zhiyu** , and their email address is listed as **xavier@astrolink[.]cn**.\\n\\n![](https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2026\/01\/beijingastrolink.png)\\n\\nA Google-translated version of Astrolink&#8217;s website, circa 2009. Image: archive.org.\\n\\nAstute readers will notice that the user **Mr.Zhu** in the Badbox 2.0 panel used the email address **xavierzhu@qq.com**. Searching this address in Constella reveals a jd.com account registered in the name of Zhu Zhiyu. A rather unique password used by this account matches the password used by the address **xavierzhu@gmail.com** , which DomainTools finds was the original registrant of astrolink[.]cn.\\n\\n## ADMIN\\n\\nThe very first account listed in the Badbox 2.0 panel &#8212; \\&#8221;admin,\\&#8221; registered in November 2020 &#8212; used the email address **189308024@qq.com**. DomainTools shows this email is found in the 2022 registration records for the domain **guilincloud[.]cn** , which includes the registrant name \\&#8221;**Huang Guilin**.\\&#8221;\\n\\nConstella finds 189308024@qq.com is associated with the China phone number **18681627767**. The breach tracking service **osint.industries** reveals this phone number is connected to a Microsoft profile created in 2014 under the name **Guilin Huang (\u6842\u6797 \u9ec4)**. The cyber intelligence platform **Spycloud** says that phone number was used in 2017 to create an account at the Chinese social media platform Weibo under the username \\&#8221;**h_guilin**.\\&#8221;\\n\\n![](https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2026\/01\/guilinhuang.png)\\n\\nThe public information attached to Guilin Huang&#8217;s Microsoft account, according to the breach tracking service osintindustries.com.\\n\\nThe remaining three users and corresponding qq.com email addresses were all connected to individuals in China. However, none of them (nor Mr. Huang) had any apparent connection to the entities created and operated by Chen Daihai and Zhu Zhiyu &#8212; or to any corporate entities for that matter. Also, none of these individuals responded to requests for comment.\\n\\nThe mind map below includes search pivots on the email addresses, company names and phone numbers that suggest a connection between Chen Daihai, Zhu Zhiyu, and Badbox 2.0.\\n\\n![](https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2026\/01\/mm-chen-xavier.png)\\n\\nThis mind map includes search pivots on the email addresses, company names and phone numbers that appear to connect Chen Daihai and Zhu Zhiyu to Badbox 2.0. Click to enlarge.\\n\\n## UNAUTHORIZED ACCESS\\n\\nThe idea that the Kimwolf botmasters could have direct access to the Badbox 2.0 botnet is a big deal, but explaining exactly why that is requires some background on how Kimwolf spreads to new devices. The botmasters figured out they could trick residential proxy services into relaying malicious commands to vulnerable devices behind the firewall on the unsuspecting user&#8217;s local network.\\n\\nThe vulnerable systems sought out by Kimwolf are primarily Internet of Things (IoT) devices like unsanctioned Android TV boxes and digital photo frames that have no discernible security or authentication built-in. Put simply, if you can communicate with these devices, you can compromise them with a single command.\\n\\nOur January 2 story featured research from the proxy-tracking firm **Synthient** , which alerted 11 different residential proxy providers that their proxy endpoints were vulnerable to being abused for this kind of local network probing and exploitation.\\n\\nMost of those vulnerable proxy providers have since taken steps to prevent customers from going upstream into the local networks of residential proxy endpoints, and it appeared that Kimwolf would no longer be able to quickly spread to millions of devices simply by exploiting some residential proxy provider.\\n\\nHowever, the source of that Badbox 2.0 screenshot said the Kimwolf botmasters had an ace up their sleeve the whole time: Secret access to the Badbox 2.0 botnet control panel.\\n\\n\\&#8221;Dort has gotten unauthorized access,\\&#8221; the source said. \\&#8221;So, what happened is normal proxy providers patched this. But Badbox doesn&#8217;t sell proxies by itself, so it&#8217;s not patched. And as long as Dort has access to Badbox, they would be able to load\\&#8221; the Kimwolf malware directly onto TV boxes associated with Badbox 2.0.\\n\\nThe source said it isn&#8217;t clear how Dort gained access to the Badbox botnet panel. But it&#8217;s unlikely that Dort&#8217;s existing account will persist for much longer: All of our notifications to the qq.com email addresses listed in the control panel screenshot received a copy of that image, as well as questions about the apparently rogue ABCD account.&#8221;,&#8221;published&#8221;:&#8221;2026-01-26T16:11:38&#8243;,&#8221;modified&#8221;:&#8221;2026-01-26T16:11:38&#8243;,&#8221;type&#8221;:&#8221;krebs&#8221;,&#8221;title&#8221;:&#8221;Who Operates the Badbox 2.0 Botnet?&#8221;,&#8221;source&#8221;:&#8221;&#8221;,&#8221;references&#8221;:&#8221;&#8221;,&#8221;id&#8221;:&#8221;KREBS:8657B84E0B5E90694CA65B56A6236AC9&#8243;,&#8221;bulletinFamily&#8221;:&#8221;blog&#8221;,&#8221;cwe&#8221;:null,&#8221;cvelist&#8221;:[],&#8221;sourceData&#8221;:&#8221;&#8221;,&#8221;sourceHref&#8221;:&#8221;&#8221;,&#8221;cvss&#8221;:{&#8220;score&#8221;:0,&#8221;severity&#8221;:&#8221;NONE&#8221;,&#8221;vector&#8221;:&#8221;NONE&#8221;,&#8221;version&#8221;:&#8221;NONE&#8221;},&#8221;cvss2&#8243;:{},&#8221;cvss3&#8243;:{&#8220;version&#8221;:&#8221;&#8221;,&#8221;vectorString&#8221;:&#8221;&#8221;,&#8221;baseScore&#8221;:0,&#8221;baseSeverity&#8221;:&#8221;&#8221;,&#8221;attackVector&#8221;:&#8221;&#8221;,&#8221;attackComplexity&#8221;:&#8221;&#8221;,&#8221;privilegesRequired&#8221;:&#8221;&#8221;,&#8221;userInteraction&#8221;:&#8221;&#8221;,&#8221;scope&#8221;:&#8221;&#8221;,&#8221;confidentialityImpact&#8221;:&#8221;&#8221;,&#8221;integrityImpact&#8221;:&#8221;&#8221;,&#8221;availabilityImpact&#8221;:&#8221;&#8221;,&#8221;cvssV3&#8243;:{&#8220;version&#8221;:&#8221;&#8221;,&#8221;vectorString&#8221;:&#8221;&#8221;,&#8221;baseScore&#8221;:0,&#8221;baseSeverity&#8221;:&#8221;&#8221;,&#8221;attackVector&#8221;:&#8221;&#8221;,&#8221;attackComplexity&#8221;:&#8221;&#8221;,&#8221;privilegesRequired&#8221;:&#8221;&#8221;,&#8221;userInteraction&#8221;:&#8221;&#8221;,&#8221;scope&#8221;:&#8221;&#8221;,&#8221;confidentialityImpact&#8221;:&#8221;&#8221;,&#8221;integrityImpact&#8221;:&#8221;&#8221;,&#8221;availabilityImpact&#8221;:&#8221;&#8221;}},&#8221;href&#8221;:&#8221;https:\/\/krebsonsecurity.com\/2026\/01\/who-operates-the-badbox-2-0-botnet\/&#8221;,&#8221;category_name&#8221;:&#8221;News&#8221;,&#8221;post_link&#8221;:&#8221;&#8221;,&#8221;product&#8221;:&#8221;&#8221;,&#8221;version&#8221;:&#8221;&#8221;,&#8221;vendor&#8221;:&#8221;&#8221;,&#8221;ai_description&#8221;:&#8221;&#8221;,&#8221;ai_severity&#8221;:&#8221;&#8221;,&#8221;ai_vendor&#8221;:&#8221;&#8221;,&#8221;ai_product&#8221;:&#8221;&#8221;,&#8221;ai_version&#8221;:&#8221;&#8221;,&#8221;ai_score&#8221;:0}<\/p>\n","protected":false},"excerpt":{"rendered":"<p>{&#8220;lastseen&#8221;:&#8221;2026-01-26T18:05:09&#8243;,&#8221;description&#8221;:&#8221;The cybercriminals in control of **Kimwolf** &#8212; a disruptive botnet that has infected more than 2 million devices &#8212; recently shared a screenshot indicating they&#8217;d&#8230;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[4],"tags":[6,8,12,119,13,33,7,11,5],"class_list":["post-37255","post","type-post","status-publish","format-standard","hentry","category-category_news","tag-cve","tag-cvss","tag-exploit","tag-krebs","tag-news","tag-none","tag-security","tag-tapic","tag-vulnerability"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.5 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Who Operates the Badbox 2.0 Botnet?_KREBS:8657B84E0B5E90694CA65B56A6236AC9 - zero redgem<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/zero.redgem.net\/?p=37255\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Who Operates the Badbox 2.0 Botnet?_KREBS:8657B84E0B5E90694CA65B56A6236AC9 - zero redgem\" \/>\n<meta property=\"og:description\" content=\"{&#8220;lastseen&#8221;:&#8221;2026-01-26T18:05:09&#8243;,&#8221;description&#8221;:&#8221;The cybercriminals in control of **Kimwolf** &#8212; a disruptive botnet that has infected more than 2 million devices &#8212; recently shared a screenshot indicating they&#8217;d...\" \/>\n<meta property=\"og:url\" content=\"https:\/\/zero.redgem.net\/?p=37255\" \/>\n<meta property=\"og:site_name\" content=\"zero redgem\" \/>\n<meta property=\"article:published_time\" content=\"2026-01-26T12:39:22+00:00\" \/>\n<meta name=\"author\" content=\"invoker\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"invoker\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"8 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=37255#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=37255\"},\"author\":{\"name\":\"invoker\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/person\\\/fbfeae8dfad117ac08a7621bee1a1dca\"},\"headline\":\"Who Operates the Badbox 2.0 Botnet?_KREBS:8657B84E0B5E90694CA65B56A6236AC9\",\"datePublished\":\"2026-01-26T12:39:22+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=37255\"},\"wordCount\":1662,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\"},\"keywords\":[\"CVE\",\"CVSS\",\"exploit\",\"krebs\",\"news\",\"NONE\",\"Security\",\"tapic\",\"Vulnerability\"],\"articleSection\":[\"category_news\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/zero.redgem.net\\\/?p=37255#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=37255\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/?p=37255\",\"name\":\"Who Operates the Badbox 2.0 Botnet?_KREBS:8657B84E0B5E90694CA65B56A6236AC9 - zero redgem\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#website\"},\"datePublished\":\"2026-01-26T12:39:22+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=37255#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/zero.redgem.net\\\/?p=37255\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=37255#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/zero.redgem.net\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Who Operates the Badbox 2.0 Botnet?_KREBS:8657B84E0B5E90694CA65B56A6236AC9\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#website\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/\",\"name\":\"zero redgem\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/zero.redgem.net\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\",\"name\":\"zero redgem\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"\",\"contentUrl\":\"\",\"width\":191,\"height\":188,\"caption\":\"zero redgem\"},\"image\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/person\\\/fbfeae8dfad117ac08a7621bee1a1dca\",\"name\":\"invoker\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"caption\":\"invoker\"},\"sameAs\":[\"https:\\\/\\\/zero.redgem.net\"],\"url\":\"https:\\\/\\\/zero.redgem.net\\\/?author=1\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Who Operates the Badbox 2.0 Botnet?_KREBS:8657B84E0B5E90694CA65B56A6236AC9 - zero redgem","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/zero.redgem.net\/?p=37255","og_locale":"en_US","og_type":"article","og_title":"Who Operates the Badbox 2.0 Botnet?_KREBS:8657B84E0B5E90694CA65B56A6236AC9 - zero redgem","og_description":"{&#8220;lastseen&#8221;:&#8221;2026-01-26T18:05:09&#8243;,&#8221;description&#8221;:&#8221;The cybercriminals in control of **Kimwolf** &#8212; a disruptive botnet that has infected more than 2 million devices &#8212; recently shared a screenshot indicating they&#8217;d...","og_url":"https:\/\/zero.redgem.net\/?p=37255","og_site_name":"zero redgem","article_published_time":"2026-01-26T12:39:22+00:00","author":"invoker","twitter_card":"summary_large_image","twitter_misc":{"Written by":"invoker","Est. reading time":"8 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/zero.redgem.net\/?p=37255#article","isPartOf":{"@id":"https:\/\/zero.redgem.net\/?p=37255"},"author":{"name":"invoker","@id":"https:\/\/zero.redgem.net\/#\/schema\/person\/fbfeae8dfad117ac08a7621bee1a1dca"},"headline":"Who Operates the Badbox 2.0 Botnet?_KREBS:8657B84E0B5E90694CA65B56A6236AC9","datePublished":"2026-01-26T12:39:22+00:00","mainEntityOfPage":{"@id":"https:\/\/zero.redgem.net\/?p=37255"},"wordCount":1662,"commentCount":0,"publisher":{"@id":"https:\/\/zero.redgem.net\/#organization"},"keywords":["CVE","CVSS","exploit","krebs","news","NONE","Security","tapic","Vulnerability"],"articleSection":["category_news"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/zero.redgem.net\/?p=37255#respond"]}]},{"@type":"WebPage","@id":"https:\/\/zero.redgem.net\/?p=37255","url":"https:\/\/zero.redgem.net\/?p=37255","name":"Who Operates the Badbox 2.0 Botnet?_KREBS:8657B84E0B5E90694CA65B56A6236AC9 - zero redgem","isPartOf":{"@id":"https:\/\/zero.redgem.net\/#website"},"datePublished":"2026-01-26T12:39:22+00:00","breadcrumb":{"@id":"https:\/\/zero.redgem.net\/?p=37255#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/zero.redgem.net\/?p=37255"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/zero.redgem.net\/?p=37255#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/zero.redgem.net\/"},{"@type":"ListItem","position":2,"name":"Who Operates the Badbox 2.0 Botnet?_KREBS:8657B84E0B5E90694CA65B56A6236AC9"}]},{"@type":"WebSite","@id":"https:\/\/zero.redgem.net\/#website","url":"https:\/\/zero.redgem.net\/","name":"zero redgem","description":"","publisher":{"@id":"https:\/\/zero.redgem.net\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/zero.redgem.net\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/zero.redgem.net\/#organization","name":"zero redgem","url":"https:\/\/zero.redgem.net\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/zero.redgem.net\/#\/schema\/logo\/image\/","url":"","contentUrl":"","width":191,"height":188,"caption":"zero redgem"},"image":{"@id":"https:\/\/zero.redgem.net\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/zero.redgem.net\/#\/schema\/person\/fbfeae8dfad117ac08a7621bee1a1dca","name":"invoker","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","caption":"invoker"},"sameAs":["https:\/\/zero.redgem.net"],"url":"https:\/\/zero.redgem.net\/?author=1"}]}},"_links":{"self":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts\/37255","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=37255"}],"version-history":[{"count":0,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts\/37255\/revisions"}],"wp:attachment":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=37255"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=37255"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=37255"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}