TF-MAL-apk.vo1d
📛 Threat Title
Malware family: vo1d
Description
ThreatFox malware family `apk.vo1d`. Printable name: vo1d.
Indicators of Compromise (0)
No indicators of compromise on this threat.
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:cyberinsider.com
Doctor Web has identified a widespread infection targeting Android TV boxes through a malware strain dubbed Android. Vo1d . This backdoor trojan has affected nearly 1.3 million devices in 197 countries, compromising system files and enabling attackers to remotely install software on users' devices.
-
web:cybersecurefox.com
Attribution signals: overlap with Vo1d botnet and Mzmess malware Quokka observed multiple cross-indicators that align the activity with the Vo1d botnet and the Mzmess malware family , including shared package prefixes, similar code strings and naming patterns, common network endpoints, and a matching delivery-and-execution pipeline.
-
web:dailysecurityreview.com
The Vo1d botnet has recently reached alarming heights, infecting over 1.59 million Android TV devices globally, impacting 226 countries. This significant surge in infections highlights the evolving nature of malware targeting consumer electronics.
-
web:github.com
Contribute to DoctorWebLtd/ malware -iocs development by creating an account on GitHub.
-
web:malpedia.caad.fkie.fraunhofer.de
According to Xlab, this malware is used to compromise Android TVs and set-top boxes, and its corresponding botnet had more than 1 million nodes observed via sinkholing (Jan 2025).
-
web:news.drweb.com
Doctor Web experts have uncovered yet another case of an Android-based TV box infection. The malware , dubbed Android. Vo1d , has infected nearly 1.3 million devices belonging to users in 197 countries. It is a backdoor that puts its components in the system storage area and, when commanded by attackers, is capable of secretly downloading and installing third-party software.
-
web:securityaffairs.com
Operators behind the Vo1d botnet have enhanced its capabilities, enabling rapid growth in recent months. In September 2024, Doctor Web researchers uncovered a malware , tracked as Vo1d , that infected nearly 1.3 million Android-based TV boxes belonging to users in 197 countries.
-
web:www.darktrace.com
Earlier this year, Darktrace investigated the Vo1d malware campaign, tracing its activity from DGA-based DNS beaconing to major cloud infrastructure and ultimately to its C2 server communications. This blog explores how Darktrace detected Vo1d and presents a detailed timeline of Cyber AI Analyst's investigation.
-
web:www.forbes.com
A massive malware botnet is turning Android TVs into cybercriminal proxies. Discover how Vo1d operates, its hidden dangers, and the steps to keep your devices safe.
-
web:www.rescana.com
The malware often creates a "secondstage" folder on the device filesystem, which contains additional payloads and scripts for ongoing operations. The use of encrypted or obfuscated communication channels, rapid domain flux, and the deployment of rootkits or privilege escalation exploits further complicate detection and remediation .
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.