172: SuperBox
Apr 7, 2026
Summary
Jack Rhysider interviews security researcher Deadass about the "Bad Box" botnet, a campaign using malicious streaming devices like the Superbox to infiltrate US homes. Deadass details how these boxes, sold on major retail platforms, contain malware that scans networks, attempts SCADA exploits, and communicates with Chinese servers. The episode explores the device's covert marketing, its potential use for corporate espionage, and the FBI's warnings, highlighting the dangers of unvetted IoT hardware in suburban households.
Topics discussed
Intro: Recalled garlic press and hacked gaming PCs
Sponsors: Delete Me and SpyCloud
Guest intro: Deadass's background in security
The Superbox discovery: Dad's pirated TV box
Network analysis: SCADA exploits and suspicious traffic
Marketing scheme: Influencers and suburban targeting
Technical deep dive: TeamViewer and hidden firmware
Hardware analysis: Fake certifications and root access
FBI warnings and the psychology of piracy
The VC Box: A new variant with Chinese links
Researcher harassment: DDoS attacks and threats
Kim Wolf botnet: Residential proxies and attacks
Geopolitical implications: Nation-state espionage
Real-world risks: Scanning devices in public spaces
Regulatory failures: Why these devices persist
Conclusion: Zero-trust mindset and future threats
Listen ad-free on Castria