Vo1d
Vo1d is a large-scale Android botnet and backdoor family targeting Android TV devices, set-top boxes, and low-cost smart-TV ecosystems, especially unofficial or modified devices and apps associated with pirated streaming.
Profile source: Mallory opens in a new tabVo1d
Family profile
Vo1d is a large-scale Android botnet and backdoor family targeting Android TV devices, set-top boxes, and low-cost smart-TV ecosystems, especially unofficial or modified devices and apps associated with pirated streaming. Public reporting first brought broad attention to the operation in 2024, and subsequent research estimated an infected population ranging from roughly 1.3 million to more than 1.6 million devices across more than 200 countries, with some telemetry indicating daily activity at even larger scale.
Vo1d is modular and resilient. It uses downloader and backdoor components, encrypted command-and-control communications, domain-generation techniques, redirector infrastructure, and multiple domains and ports to maintain control and complicate disruption. Researchers have documented custom string and payload decryption, RSA-protected communications, and evolving downloader logic intended to hinder analysis and infrastructure takeover. Observed monetization includes residential proxy enablement and traffic manipulation, including ad-fraud or fake-traffic generation.
A notable component associated with Vo1d is Popa, a proxy plugin or SDK that registers infected devices into a residential proxy network and relays third-party traffic through victim connections. Popa has been observed on compromised Android TV boxes and in trojanized or modified consumer applications, including streaming-related software and other apps. This component is widely described as a networking layer within the broader Vo1d ecosystem rather than the entirety of the malware itself. Research has also identified overlap between Popa-related infrastructure and commercialized proxy ecosystems, although attribution of operational control remains disputed in some reporting.
The initial infection vector for Vo1d has not been conclusively established, but the malware is strongly associated with unofficial Android-based TV boxes, preloaded or modified firmware, and bundled applications from untrusted distribution channels. Devices in this ecosystem often lack timely patching and may ship with unwanted or malicious components, making them attractive for persistent botnet enrollment.
Vo1d has been linked in technical reporting to other major Android botnet ecosystems through shared code traits, infrastructure overlaps, or related deployment environments, including Triada, BADBOX, and Keenadu, though these links do not by themselves prove common authorship. The malware’s scale, persistence on consumer media devices, and use as proxy infrastructure make it significant both for cybercrime operations and for downstream abuse such as scraping, credential attacks, traffic laundering, and concealment of malicious activity.
MITRE ATT&CK
Vo1d in ATT&CK
11 distinct techniquesReporting
Research mentioning Vo1d
Google Dismantles NetNut Residential Proxy That Hacked 2 Million Home Devices - Cyber Security News
Popa functions as a plugin component of the larger Vo1d botnet, which targets unofficial Android-based TV boxes bundled with pirated streaming apps such as CRICFy, DooFlix, and Flixoid.
‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm - Malware News - Malware Analysis, News and Indicators
Experts say Popa is a plugin component associated with the Vo1d botnet, a large-scale malware campaign targeting unofficial Android-based TV boxes.
‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm - Krebs on Security
Experts say Popa is a plugin component associated with the Vo1d botnet, a large-scale malware campaign targeting unofficial Android-based TV boxes.
Popa: From Sourcing to Distribution | Synthient
As highlighted in public research by organizations such as XLab, the SDKs has been linked to larger operations, including the Vo1d campaign.
Finding “Popa”: When Your Smart TV Stops Being Yours - Qurium Media Foundation
Popa has been found as a plugin component associated with the Vo1d botnet, a large-scale malware campaign targeting Android-based TV boxes and similar devices.
Cybercriminals move deeper into networks, hiding in edge infrastructure - Help Net Security
Vo1d followed with 2,519,125...
Android TV Botnet Landscape: Bigpanzi, Kimwolf, and the Misattribution of Kimsuky - Breakglass Intelligence - Breakglass Intelligence
Vo1d (est. 2024, unknown origin) uses Bigpanzi-like string decryption but operates independently. 1.6M+ device fleet.
Keenadu backdoor found preinstalled on Android devices, powers Ad fraud campaign
Investigators also linked Keenadu to major Android botnets, including Triada, BADBOX, and Vo1d.