Darknet Diaries Darknet Diaries

172: SuperBox

Apr 7, 2026

Summary

Jack Rhysider interviews security researcher Deadass about the "Bad Box" botnet, a campaign using malicious streaming devices like the Superbox to infiltrate US homes. Deadass details how these boxes, sold on major retail platforms, contain malware that scans networks, attempts SCADA exploits, and communicates with Chinese servers. The episode explores the device's covert marketing, its potential use for corporate espionage, and the FBI's warnings, highlighting the dangers of unvetted IoT hardware in suburban households.

Topics discussed

Intro: Recalled garlic press and hacked gaming PCs Sponsors: Delete Me and SpyCloud Guest intro: Deadass's background in security The Superbox discovery: Dad's pirated TV box Network analysis: SCADA exploits and suspicious traffic Marketing scheme: Influencers and suburban targeting Technical deep dive: TeamViewer and hidden firmware Hardware analysis: Fake certifications and root access FBI warnings and the psychology of piracy The VC Box: A new variant with Chinese links Researcher harassment: DDoS attacks and threats Kim Wolf botnet: Residential proxies and attacks Geopolitical implications: Nation-state espionage Real-world risks: Scanning devices in public spaces Regulatory failures: Why these devices persist Conclusion: Zero-trust mindset and future threats
Listen ad-free on Castria