The SuperBox lawsuit campaign is a coordinated push by DISH Network and its subsidiary Sling TV against people who sell SuperBox Android streaming devices preloaded with pirated channels, and the cases have already produced million-dollar judgments, permanent injunctions, and retailer delistings. If you sell these boxes, the financial exposure is real and documented. If you own one, the criminal legal risk is smaller, but federal investigators say the hardware itself may be enrolling your home internet connection into a criminal botnet.
What DISH and Sling Have Won in Court
In May 2024, DISH and Sling TV sued two individuals, Marcelino Padilla and Danny Contreras, in the U.S. District Court for the Central District of California. The complaint alleged they sold vSeeBox, Tanggula, and SuperBox devices preloaded with pirated streaming services, marketing them for a one-time $350 fee with “no monthly fees or silly codes.”
The case ended in a final judgment and permanent injunction. The defendants were ordered to pay $1.25 million in damages and were permanently barred from distributing the services. A separate case against another seller produced $405,000 in damages tied to 162 devices. In 2025, DISH filed a new suit against a SuperBox reseller, alleging the device was streaming content ripped directly from Sling TV.
DISH’s broader anti-piracy docket has generated judgments ranging from hundreds of thousands to tens of millions of dollars, along with injunctions that reach ISPs, payment processors, and hosting providers.
What the Lawsuits Claim SuperBox Devices Do
The hardware itself is a generic Android-powered set-top box, and it is not inherently illegal. What draws the lawsuits is the software configuration. Sellers advertise the devices as “fully loaded” or “plug and play ready,” preloaded with third-party app stores that deliver copyrighted channels and films without permission from the rights holders.
The key apps historically bundled onto SuperBox devices include Blue TV, which streams hundreds of pirated live broadcast and cable channels, and Blue VOD, which serves thousands of pirated films and TV shows. Users can access NFL Sunday Ticket games, UFC fights, ESPN, and channels like Sky Sports that aren’t even licensed for U.S. distribution.
According to DISH’s California complaint, its technical analysis confirmed that identifiers unique to its own internet transmissions appeared on the seized devices, evidence that content was being ripped straight from its services. The suit alleged the defendants bypassed Widevine DRM protections to retransmit encrypted DISH and Sling channel streams, including ESPN, MLB Network, and AMC.
SuperBox’s official position, per statements from the company, is that it “only sells the hardware device” and that customers are responsible for the apps they install. The company’s public contact information consists of a WhatsApp number with a Hong Kong country code.
What Sellers Are Exposed To
DISH’s civil cases against device sellers rest on two federal statutes. The Digital Millennium Copyright Act’s anti-circumvention provisions carry statutory damages of up to $2,500 per violation. The Electronic Communications Privacy Act allows the greater of $100 per day or $10,000 per violation.
Initial demand letters to individual sellers typically range from $3,500 to $15,000. Statutory exposure can climb to $110,000 per violation in cases involving the sale of access codes. Multiply that by the number of devices moved, and the arithmetic behind a $1.25 million judgment stops looking surprising.
The Protecting Lawful Streaming Act, signed into law on December 27, 2020, adds a criminal layer. It elevated willful commercial streaming piracy from a misdemeanor to a felony, with penalties of up to three years in prison for a first offense, five years for cases involving pre-release content or live sporting events, and ten years for repeat offenders. The law targets operators and providers of illegal streaming services, not viewers.
What Buyers Are Actually Risking
For buyers, the legal picture is narrower. Enforcement action has focused on resellers and operators rather than individual viewers, and the Protecting Lawful Streaming Act explicitly excludes ordinary users. Using these devices to access unlicensed content still amounts to copyright infringement in principle, and rights holders can shift strategies at any time, but there is no reported pattern of civil suits against end users.
The bigger practical risk is cybersecurity. A November 2025 Krebs on Security investigation found that SuperBox devices contact servers associated with residential proxy services and ship with powerful, unauthorized network tools including Tcpdump and Netcat. The devices engage in DNS hijacking and ARP poisoning to bypass network controls. In plain terms, a SuperBox in your living room may be routing traffic for cybercriminals through your home internet connection.
Those findings overlap with a broader federal warning. On June 5, 2025, the FBI released a public service announcement about the BADBOX 2.0 botnet, describing it as compromising millions of IoT devices, most of them low-cost, uncertified Android devices manufactured in China. HUMAN Security’s Satori Threat Intelligence team identified BADBOX 2.0 as the largest botnet of infected connected-TV devices ever uncovered, spanning over one million devices across 222 countries.
The operation works by embedding a backdoor called BB2DOOR in device firmware before shipping, or by infecting devices when users download apps from unofficial marketplaces. That second path is exactly the setup SuperBox requires. At its peak, the botnet’s hidden-ad fraud scheme generated five billion fraudulent bid requests per week, and compromised devices were sold on as residential proxy nodes for downstream attacks.
The FBI advised consumers to watch for warning signs: devices that require disabling Google Play Protect, use suspicious app marketplaces, or are marketed as “unlocked” for free content. The agency recommended disconnecting suspicious devices from home networks entirely. In July 2025, Google sued the individuals in China responsible for creating BADBOX 2.0.
There is also the mundane risk that the pirated services simply stop working. They frequently get shut down without notice, leaving buyers with an expensive box that no longer streams anything.
Where the Devices Are Still Sold
In September 2022, Amazon and Walmart removed roughly a dozen SuperBox listings after Fierce Video contacted them about the piracy connections. Walmart said it had “a robust trust and safety program” and pulled all SuperBox models. Amazon said it took “corrective actions with respect to products that violate our policies,” though approximately 20 versions reportedly remained on its platform after the initial sweep.
The removals didn’t hold. As of late 2025, SuperBox devices remained widely available on Amazon, Walmart, BestBuy, and Newegg, typically sold by third-party merchants through those platforms’ marketplaces. Amazon reportedly removes individual listings only when flagged by customers, after which new product pages for the same device appear. Some sellers list the boxes under generic titles like “modem and router combo” to evade detection.
Laws That May Change the Picture
In January 2025, Representative Zoe Lofgren introduced the Foreign Anti-Digital Piracy Act (H.R. 791), which would create a site-blocking mechanism for foreign piracy websites. The bill targets online services rather than device sales and remained in its introductory stage as of mid-2026.
Despite the lawsuits, retailer removals, FBI warnings, and Google’s own suit against the botnet operators, reporting through early 2026 shows no meaningful slowdown in SuperBox adoption. The enforcement pressure is on the sellers, and the judgments against them are stacking up.