BadBox in the Living Room: Forensic Analysis of a VSeeBox V3 Plus

A VSeeBox V3 Plus had been sitting on a quarantine VLAN in my living room since last year. I’d isolated it after suspecting a BadBox infection and hadn’t gotten around to pulling it apart. This weekend I finally did. The short version: the device is infected with BadBox 2.0 malware. The SOCKS5 proxy was live and accepting connections from residential IPs. The DNS blocklist was being bypassed with encrypted DNS. And one domain in the traffic trace points directly back to VSeeBox’s own infrastructure. ...

July 6, 2026 · 6 min · Adam Behn