That cheap TV box in your lounge is working for someone else
- Wayne Du Bruyn
- Jul 15
- 4 min read

There is a good chance a device in your home spent last night attacking websites on another continent. Not your laptop. Not your phone. The R700 Android TV box someone bought to stream sport for free.
Security researchers at QiAnXin XLab spent the end of 2025 tracking a botnet called Kimwolf. At its peak they counted around 1.8 million infected devices, almost all of them Android TV boxes, set-top boxes and tablets sitting in ordinary homes. South Africa is on the shortlist of countries with the highest concentration of infections, alongside Brazil, India, the US, Argentina and the Philippines.
The numbers are hard to take in. Between 19 and 22 November 2025, the botnet issued about 1.7 billion attack commands in three days. One of its control domains briefly ranked first on Cloudflare's list of the top 100 most-queried domains. For a moment, a criminal botnet was busier than Google.
How the boxes get infected
Nobody hacked these devices in the movie sense. Many of the no-name boxes sold online, the SuperBOX and X96Q and MX10 types, ship with the problem already installed or pick it up through the unofficial app stores you need for the "free" streaming they're sold on. Brian Krebs reported that a large share of them come with residential proxy software baked in from the factory. Your bandwidth gets resold to strangers before you've finished the unboxing.
And here's the detail from the Krebs investigation that should worry anyone with a smart home. Kimwolf doesn't stop at the infected box. It abuses residential proxy networks to reach back into the local network behind your router, past the firewall, and infect other devices sitting on the same subnet. Krebs put it bluntly: everything you thought you knew about the security of the network behind your router "probably is now dangerously out of date".
XLab also found that over 96% of the botnet's commands weren't attacks at all. They were proxy jobs. The operators mostly rent out your internet connection for ad fraud, account takeovers and content scraping. You pay Vodacom or Afrihost for the line. Someone in another country collects the income.
Why I keep going on about infrastructure
Think of every device on your network as someone you've given keys to the building. A KNX actuator from Hager or Ekinex is an employee with one job, no phone and no internet access. It physically cannot call home because it lives on a twisted-pair bus that doesn't speak IP. A R700 streaming box from a brand you've never heard of is a stranger you've handed the master key, and nobody is checking what he does at night.
Most of what people call a smart home today is forty wifi devices from twelve brands, all sitting on one flat network with the laptops, the phones and the NAS. Every one of those devices is a separate little computer with its own firmware, its own update policy and its own idea of which overseas server it should talk to. When one of them turns, it has line of sight to everything you own.
A KNX installation fails in the opposite direction. Lighting, heating, shading and switching run on a dedicated wired bus. No IP, no cloud account, no firmware fetched from a mystery server. The bus keeps working when the internet is down, and it keeps working when the internet is compromised, which after this year feels like the more important property.
The parts of my installations that do touch the network get treated with suspicion by design. The KNX IP interface, the Home Assistant machine and the 1Home gateway sit on their own VLAN with firewall rules that say exactly who may talk to what. Media devices and anything cheap and cloudy go in their own segregated corner where they can be as badly behaved as they like without reaching the things that matter. On a UniFi network this is an afternoon's work, not a research project. And where a KNX installation does need IP connectivity between parts, KNX Secure exists precisely to encrypt that traffic rather than trusting the network it crosses.
What to actually do
If you own one of those cheap streaming boxes, unplug it. Not after the weekend. The whole product category is compromised at the supply chain level, and no setting inside the box fixes a device that arrived infected.
Then stop treating your home network as one big trusted space, because the attackers stopped treating it that way some time ago. Put IoT devices on their own network. Change the router's default password, update its firmware, and if it's more than five years old, replace it.
And when you plan a renovation or a new build, ask a harder question than "which app does it use". Ask what happens to the house when a device on the network goes rogue. A home where the core functions run on a wired, non-IP bus has a very different answer to one where the lights are forty little computers on the wifi.
The convenience of the cheap route is real. So is the cost. It just doesn't show up on the invoice.
If you're planning a project and want the network and the automation designed as one system instead of an accumulation of gadgets, get in touch. No pitch, just a conversation about what the project needs.
Wayne | KNX Logic
wayne@knxlogic.co.za | 082 564 3982 | www.knxlogic.co.za




Comments