Vo1d is a large-scale Android botnet and backdoor ecosystem that primarily targets unofficial Android-based TV boxes, smart projectors, and related embedded consumer devices. It has been observed at firmware or supply-chain level on some devices before sale, enabling persistent compromise without obvious user-visible symptoms. Public reporting has also associated Vo1d with low-cost streaming devices bundled with pirated or modified media applications, and with broader Android malware ecosystems that overlap with BADBOX, Triada, and Keenadu infrastructure or tradecraft.
A defining function of Vo1d is conversion of infected devices into residential proxy nodes. Compromised systems register with command infrastructure, receive relay assignments, and forward third-party traffic through the victim’s home or device IP address. Research on the Popa plugin, which is associated with the Vo1d ecosystem, indicates that Vo1d can maintain long-lived encrypted or tunneled communications and support large proxy backends used for scraping, account abuse, infrastructure obfuscation, and other criminal activity. At scale, Vo1d infections have been measured in the millions of devices globally.
Vo1d has been linked to Android TV boxes and similar devices running Android forks, including cases where malicious components appear embedded in firmware prior to purchase. Infection vectors have not been fully determined in all cases, but supply-chain compromise and preinstallation on unofficial streaming hardware are strongly associated with the malware. Related reporting also ties Vo1d-associated proxy functionality to bundled SDK components in modified streaming applications and other software that silently enroll devices into proxy networks.
Operationally, Vo1d acts as a backdoor and botnet platform rather than a simple standalone proxy tool. It communicates with command-and-control infrastructure in multiple stages, registers device metadata, maintains persistent heartbeat traffic, and can expose infected devices as relay or exit nodes. The ecosystem’s plugin architecture, especially through Popa, suggests modular networking functionality designed to monetize compromised devices’ bandwidth and connectivity. Vo1d has also been discussed alongside other major Android botnets competing for the same vulnerable smart-TV and TV-box population.
Vo1d is notable for its scale, stealth, and likely supply-chain footholds in consumer Android media devices. Its abuse of residential connectivity creates downstream risk for victims, including reputational exposure, unwanted relay of malicious traffic, and potential secondary compromise paths into local networks.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
16 distinct techniques documented for this family, organized by ATT&CK tactic.
The malware was capable of running arbitrary executables and downloading and installing any APKs.
The C2 infrastructure responds to the registration by assigning the device a specific proxy role. The response is a structured data object containing a proxy host and port that the device will use to route criminal traffic through the victim's home internet connection.
Within 2.17 seconds of powering on — before any user touches the remote — the device contacts ota.triplesai[.]com:8080 over HTTP. The traffic mimics a legitimate over-the-air firmware update check, but the payload contains the device's complete fingerprint.
A consumer projector was generating DNS queries on a precise ~65-second cycle... The domain: .o.fecebbbk[.]xyz... The DNS responses are configured with a deliberate 60-second TTL... every infected device worldwide automatically follows within 60 seconds.
Once active, it silently enrolls the device as a residential proxy node — routing criminal internet traffic through the victim's home IP address without their knowledge or consent.
Bundled in the same installer, registered as a NuGet dependency, and activated whenever the VPN is not connected, is Neunative: a residential-proxy SDK that turns the user's machine into an exit node for third-party traffic.
The hostnames in peer_servers are rotating front domains. For a single fleet the director returns both sN.viki-play[.]com:6000 and sN.star-layer[.]com:6000 ... The sN identifier and IP are the stable node identity. The domain is disposable.
Xlab disclosed the following domains as part of their command and control (C2)... the Popa plugin retrieves the address of an operational backend server... In the case of Vo1d, the main botnet infects and manages devices, while the Popa module can be later added...
86 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
23 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A larger botnet of which Popa/NetNut is described as a plugin component; it targets unofficial Android-based TV boxes distributed with pirated streaming apps.
Large-scale botnet/malware campaign targeting unofficial Android-based TV boxes; Popa is described as a plugin component tied to this ecosystem.
Large-scale botnet/malware campaign targeting unofficial Android-based TV boxes; Popa is described as a plugin component associated with it.
Referenced only as a campaign/operation linked in prior public research to broader activity involving the SDK.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.