Skip to content
Malware family

Vo1d

Vo1d is a large-scale Android botnet and backdoor family targeting Android TV devices, set-top boxes, and low-cost smart-TV ecosystems, especially unofficial or modified devices and apps associated with pirated streaming.

Profile source: Mallory opens in a new tab

Vo1d

Family profile

Vo1d is a large-scale Android botnet and backdoor family targeting Android TV devices, set-top boxes, and low-cost smart-TV ecosystems, especially unofficial or modified devices and apps associated with pirated streaming. Public reporting first brought broad attention to the operation in 2024, and subsequent research estimated an infected population ranging from roughly 1.3 million to more than 1.6 million devices across more than 200 countries, with some telemetry indicating daily activity at even larger scale.

Vo1d is modular and resilient. It uses downloader and backdoor components, encrypted command-and-control communications, domain-generation techniques, redirector infrastructure, and multiple domains and ports to maintain control and complicate disruption. Researchers have documented custom string and payload decryption, RSA-protected communications, and evolving downloader logic intended to hinder analysis and infrastructure takeover. Observed monetization includes residential proxy enablement and traffic manipulation, including ad-fraud or fake-traffic generation.

A notable component associated with Vo1d is Popa, a proxy plugin or SDK that registers infected devices into a residential proxy network and relays third-party traffic through victim connections. Popa has been observed on compromised Android TV boxes and in trojanized or modified consumer applications, including streaming-related software and other apps. This component is widely described as a networking layer within the broader Vo1d ecosystem rather than the entirety of the malware itself. Research has also identified overlap between Popa-related infrastructure and commercialized proxy ecosystems, although attribution of operational control remains disputed in some reporting.

The initial infection vector for Vo1d has not been conclusively established, but the malware is strongly associated with unofficial Android-based TV boxes, preloaded or modified firmware, and bundled applications from untrusted distribution channels. Devices in this ecosystem often lack timely patching and may ship with unwanted or malicious components, making them attractive for persistent botnet enrollment.

Vo1d has been linked in technical reporting to other major Android botnet ecosystems through shared code traits, infrastructure overlaps, or related deployment environments, including Triada, BADBOX, and Keenadu, though these links do not by themselves prove common authorship. The malware’s scale, persistence on consumer media devices, and use as proxy infrastructure make it significant both for cybercrime operations and for downstream abuse such as scraping, credential attacks, traffic laundering, and concealment of malicious activity.

MITRE ATT&CK

Vo1d in ATT&CK

11 distinct techniques

Reporting

Research mentioning Vo1d

Jul 3
Cyber Security News

Google Dismantles NetNut Residential Proxy That Hacked 2 Million Home Devices - Cyber Security News

Popa functions as a plugin component of the larger Vo1d botnet, which targets unofficial Android-based TV boxes bundled with pirated streaming apps such as CRICFy, DooFlix, and Flixoid.

Jun 18
Malware News

‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm - Malware News - Malware Analysis, News and Indicators

Experts say Popa is a plugin component associated with the Vo1d botnet, a large-scale malware campaign targeting unofficial Android-based TV boxes.

Jun 18
Krebs On Security

‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm - Krebs on Security

Experts say Popa is a plugin component associated with the Vo1d botnet, a large-scale malware campaign targeting unofficial Android-based TV boxes.

Jun 18
Synthient

Popa: From Sourcing to Distribution | Synthient

As highlighted in public research by organizations such as XLab, the SDKs has been linked to larger operations, including the Vo1d campaign.

Jun 18
Qurium News

Finding “Popa”: When Your Smart TV Stops Being Yours - Qurium Media Foundation

Popa has been found as a plugin component associated with the Vo1d botnet, a large-scale malware campaign targeting Android-based TV boxes and similar devices.

Apr 8
Help Net Security

Cybercriminals move deeper into networks, hiding in edge infrastructure - Help Net Security

Vo1d followed with 2,519,125...

Apr 3
Breakglass Intel

Android TV Botnet Landscape: Bigpanzi, Kimwolf, and the Misattribution of Kimsuky - Breakglass Intelligence - Breakglass Intelligence

Vo1d (est. 2024, unknown origin) uses Bigpanzi-like string decryption but operates independently. 1.6M+ device fleet.

Feb 18
Security Affairs

Keenadu backdoor found preinstalled on Android devices, powers Ad fraud campaign

Investigators also linked Keenadu to major Android botnets, including Triada, BADBOX, and Vo1d.

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.