Android.Vo1d is an Android backdoor that has been observed infecting large numbers of Android-based TV boxes worldwide. It embeds components into the system partition and establishes durable execution by modifying multiple startup and system mechanisms, including recovery-related startup scripts, root-management startup hooks, and the debugger daemon chain. This multi-pronged persistence design appears intended to ensure autostart across heterogeneous firmware builds and rooted devices.
Its core functionality is implemented through cooperating modules commonly referred to as vo1d and wd. These components can launch and monitor one another, download and execute additional payloads under attacker control, and install third-party Android applications found in monitored locations. One module also deploys an additional encrypted daemon, indicating a staged architecture designed for long-term control and flexible payload delivery. The malware’s naming reflects an attempt to resemble a legitimate Android system component, supporting stealth and operator deception.
Android.Vo1d has primarily been associated with compromised Android TV box firmware rather than a confirmed user-driven installation flow. The initial infection vector has not been conclusively established. Plausible explanations include prior compromise through exploitation of unpatched Android vulnerabilities to obtain elevated privileges, or distribution through unofficial or tampered firmware images that already include root access. The malware’s dependence on system-area modification indicates privileged execution during installation.
The threat is notable for targeting low-cost Android TV devices that often run outdated Android versions, may no longer receive security updates, and in some cases reportedly misrepresent their actual platform version. This ecosystem makes such devices attractive for persistent firmware-level compromise and post-sale monetization or botnet-style reuse. Android.Vo1d’s ability to covertly fetch and install additional software means infected devices can be repurposed for follow-on malicious activity at operator discretion.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
13 distinct techniques documented for this family, organized by ATT&CK tactic.
The debuggerd file is a daemon that is typically used to create reports on occurred errors. But when the TV box was infected, this file was replaced by the script that launches the wd component.
Moreover, it monitors specified directories and installs the APK files that it finds in them.
The install-recovery.sh file is a script that is present on most Android devices. It runs when the operating system is launched... Android.Vo1d has registered the autostart for the wd component in this file.
“The install-recovery.sh file is a script… It runs when the operating system is launched… Android.Vo1d has registered the autostart for the wd component in this file.” | “The daemonsu file… is launched by the operating system when it starts… Android.Vo1d registered itself in this file, too, having also set up autostart for the wd module.”
The install-recovery.sh file is a script that is present on most Android devices. It runs when the operating system is launched... Android.Vo1d has registered the autostart for the wd component in this file.
One possible infection vector could be an attack by an intermediate malware that exploits operating system vulnerabilities to gain root privileges.
“The install-recovery.sh file is a script… It runs when the operating system is launched… Android.Vo1d has registered the autostart for the wd component in this file.” | “The daemonsu file… is launched by the operating system when it starts… Android.Vo1d registered itself in this file, too, having also set up autostart for the wd module.”
One possible infection vector could be an attack by an intermediate malware that exploits operating system vulnerabilities to gain root privileges.
The trojan’s authors probably tried to disguise one if its components as the system program /system/bin/vold, having called it by the similar-looking name “vo1d”
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Android backdoor (notably on TV boxes/firmware infections) that persists in the system area and can covertly download and install additional software on attacker command.
Firmware-level trojan affecting Android TV boxes; new versions observed in 2025 following initial discovery in 2024.
Android trojan affecting TV box firmware; new versions observed infecting devices in 2025 (originally reported in 2024).
Backdoor trojan (noted on Android TV boxes with infected firmware) that persists in the system area and covertly downloads/installs additional software on attacker command.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.