Vo1d is a large Android TV botnet first publicly associated with activity observed in 2024. It is assessed as a distinct operation from Bigpanzi despite some overlapping code characteristics, including Bigpanzi-like string decryption. Vo1d has been described as operating independently and maintaining a device fleet exceeding 1.6 million compromised systems. The botnet is part of a broader ecosystem of criminal Android TV malware competing for control of vulnerable consumer streaming devices. Vo1d targets Android TV devices and related set-top boxes, a device class widely abused for illicit monetization. Reported activity places it among the major botnet families affecting this ecosystem alongside Bigpanzi, Kimwolf, and BADBOX. High-confidence reporting supports its role as a botnet operation affecting large numbers of devices globally, but the available facts here do not firmly establish a specific operator identity, country of origin, or a detailed victim-country distribution. The operation appears financially motivated, consistent with criminal control of consumer devices at scale for monetizable botnet use. However, the supplied facts do not directly document Vo1d’s full monetization model, specific malware components, or complete post-compromise tradecraft beyond its classification as a botnet and its overlap in technical lineage with other Android TV malware families.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
8 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.