Security researchers have identified that certain Android-based digital photo frames, particularly those using the Uhale platform, are downloading and executing malware at boot time. The devices, which are rooted by default and have disabled SELinux, automatically update their Uhale app from China-based servers and subsequently download malicious payloads linked to the Vo1d botnet and Mzmess malware families. The vulnerabilities, including over a dozen security issues with 11 assigned CVEs, allow the malware to persist and execute on every reboot, with the manufacturer failing to respond to multiple security notifications.
The Vo1d malware, first observed in September 2024, has rapidly evolved into one of the most widespread Android botnets, targeting smart TVs, TV boxes, and now digital photo frames. Vo1d is capable of installing additional payloads, running proxy services, and conducting ad fraud, with infection estimates reaching up to 1.6 million devices globally. The malware employs domain generation algorithms for resilient command-and-control, and recent activity has shown a surge in infections, particularly in South Africa. The sophistication of Vo1d, including obfuscation and encryption, makes detection and remediation challenging for affected users and organizations.

Pull IOCs and campaign context straight into your stack.
4 events from the most recent confirmed update back to the earliest known activity.
Quokka reported the vulnerabilities and malware-related findings to ZEASN, now branded as Whale TV, the company behind the Uhale platform used by many rebranded digital frames. According to the report, ZEASN did not respond.
Quokka reported that the downloaded payloads showed indicators of links to the Vo1d botnet and the Mzmess/Mezmess malware families. The firm also identified 17 security issues in affected frames, including insecure TLS handling, command injection in the update process, unauthenticated file upload, and insecure WebView behavior.
Some Android-based digital picture frames using the Uhale platform were observed auto-updating the Uhale app to version 4.2.0, after which the app downloaded and executed a JAR/DEX payload from China-based servers on every subsequent boot. Researchers said the initial infection vector remained unclear.
Darktrace published research focused on detecting the Vo1d botnet, adding technical visibility into the threat's activity and behavior. The publication indicates ongoing industry analysis of Vo1d around the same period as the photo frame findings.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.