Vo1d is a large-scale Android botnet targeting unofficial Android TV boxes and related consumer streaming devices. First publicly disclosed in 2024, it has been observed on more than a million devices globally. Infections are associated with compromised firmware or supply-chain distribution; the original infection vector has not been conclusively established. Vo1d can enroll affected devices into residential proxy infrastructure, allowing third-party traffic to be relayed through victims’ residential internet connections without their knowledge. The Popa component has been identified as a proxy and tunneling plugin associated with the Vo1d ecosystem. Vo1d activity has been linked to devices running pirated or modified streaming applications, and its proxy infrastructure has overlaps with broader Android proxy-botnet activity, including BADBOX-related operations. Public reporting has not established a definitive operator attribution for Vo1d.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
16 distinct techniques documented for this family, organized by ATT&CK tactic.
The malware was capable of running arbitrary executables and downloading and installing any APKs.
The C2 infrastructure responds to the registration by assigning the device a specific proxy role. The response is a structured data object containing a proxy host and port that the device will use to route criminal traffic through the victim's home internet connection.
Within 2.17 seconds of powering on — before any user touches the remote — the device contacts ota.triplesai[.]com:8080 over HTTP. The traffic mimics a legitimate over-the-air firmware update check, but the payload contains the device's complete fingerprint.
A consumer projector was generating DNS queries on a precise ~65-second cycle... The domain: .o.fecebbbk[.]xyz... The DNS responses are configured with a deliberate 60-second TTL... every infected device worldwide automatically follows within 60 seconds.
Once active, it silently enrolls the device as a residential proxy node — routing criminal internet traffic through the victim's home IP address without their knowledge or consent.
Bundled in the same installer, registered as a NuGet dependency, and activated whenever the VPN is not connected, is Neunative: a residential-proxy SDK that turns the user's machine into an exit node for third-party traffic.
The hostnames in peer_servers are rotating front domains. For a single fleet the director returns both sN.viki-play[.]com:6000 and sN.star-layer[.]com:6000 ... The sN identifier and IP are the stable node identity. The domain is disposable.
Xlab disclosed the following domains as part of their command and control (C2)... the Popa plugin retrieves the address of an operational backend server... In the case of Vo1d, the main botnet infects and manages devices, while the Popa module can be later added...
113 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
28 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware / Outils # JarService (loader) zhima (other) BADBOX (botnet) Vo1d (other)
Referenced only as a comparison point for large-scale abuse of connected Android devices.
Mentioned only as part of Kaspersky detection verdict naming, not analyzed as a malware family in the article.
A larger botnet of which Popa/NetNut is described as a plugin component; it targets unofficial Android-based TV boxes distributed with pirated streaming apps.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.