Vo1d is a large-scale Android malware operation targeting unofficial Android-based TV boxes and related consumer streaming devices. It is widely described as a backdoor-driven botnet that has infected well over a million devices globally, with public estimates placing its footprint around 1.3 to 1.6 million devices across more than 200 countries. The malware ecosystem is associated with low-cost or unofficial smart TV hardware and pirated or modified streaming applications, and some reporting indicates infections may be preinstalled on devices before sale. Vo1d has also been discussed alongside other Android botnet ecosystems such as BADBOX and Triada, with some infrastructure overlap noted between Vo1d-related components and Triada modules, although a definitive operational relationship is not established.
A notable component associated with Vo1d is Popa, a plugin or SDK-like module that enrolls infected devices into a residential proxy network. In this role, compromised devices act as relay or exit nodes for third-party traffic, maintaining encrypted tunnels and opening communication channels on demand. Research linking Popa to the broader Vo1d ecosystem indicates that Vo1d-infected Android TV devices can be monetized through proxying activity rather than solely through traditional botnet tasks. This proxy layer has been tied to large-scale scraping, account abuse, and infrastructure obfuscation, and has been observed sharing backend architecture with proxy components embedded in consumer software outside the Android TV ecosystem.
Vo1d primarily targets Android-based TV boxes and similar embedded consumer devices. Public reporting has not conclusively established the original infection vector, but the campaign has been repeatedly associated with unofficial devices and bundled streaming software. The malware’s scale, persistence in the Android TV ecosystem, and use of modular proxy functionality make it one of the more prominent Android botnet families affecting consumer media devices.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
11 distinct techniques documented for this family, organized by ATT&CK tactic.
The malware was capable of running arbitrary executables and downloading and installing any APKs.
For each peer server, the SDK opens a TLS connection on port 6000 and speaks a proprietary binary protocol.
Bundled in the same installer, registered as a NuGet dependency, and activated whenever the VPN is not connected, is Neunative: a residential-proxy SDK that turns the user's machine into an exit node for third-party traffic.
The hostnames in peer_servers are rotating front domains. For a single fleet the director returns both sN.viki-play[.]com:6000 and sN.star-layer[.]com:6000 ... The sN identifier and IP are the stable node identity. The domain is disposable.
Xlab disclosed the following domains as part of their command and control (C2)... the Popa plugin retrieves the address of an operational backend server... In the case of Vo1d, the main botnet infects and manages devices, while the Popa module can be later added...
81 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
22 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A larger botnet of which Popa/NetNut is described as a plugin component; it targets unofficial Android-based TV boxes distributed with pirated streaming apps.
Large-scale botnet/malware campaign targeting unofficial Android-based TV boxes; Popa is described as a plugin component tied to this ecosystem.
Large-scale botnet/malware campaign targeting unofficial Android-based TV boxes; Popa is described as a plugin component associated with it.
Referenced only as a campaign/operation linked in prior public research to broader activity involving the SDK.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.