logo

New Vo1d malware infects 1.3 million Android TV streaming boxes

ID: 150bfb0b-4100-50ff-8970-586da946976b

STIX ID: report--150bfb0b-4100-50ff-8970-586da946976b

Feed Name: Bleeping Computer

Threat Score
78/100

Date Published: 2024-09-12

Date Updated: 2026-04-20

Author: Lawrence Abrams

...
...

A widespread Vo1d backdoor campaign has infected roughly 1.3 million off‑brand Android (AOSP) streaming boxes in over 200 countries; the malware uses modified startup scripts (install-recovery.sh, daemonsu, debuggerd) for persistence, comprises multiple components (vo1d, wd, encrypted daemons) that can download and execute payloads and install APKs, and Dr.Web has published IOCs and recommendations to update firmware and remove vulnerable devices from the internet.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.