ZeroSecurity - Information Security News
  • Home
  • Security
    • Exploits
    • Mobile Security
  • Malware
  • Breaches
  • Crypto
  • Privacy
  • Tech
    • AI
    • Downloads
      • Malwarebytes
      • Exploits
      • Paper Downloads
    • Reviews
No Result
View All Result
SUBSCRIBE
ZeroSecurity - Information Security News
  • Home
  • Security
    • Exploits
    • Mobile Security
  • Malware
  • Breaches
  • Crypto
  • Privacy
  • Tech
    • AI
    • Downloads
      • Malwarebytes
      • Exploits
      • Paper Downloads
    • Reviews
No Result
View All Result
ZeroSecurity - Information Security News
No Result
View All Result
Home Malware

Massive Backdoor Infection Hits 1.3 Million Android-Based Streaming Devices

Paul by Paul
September 16, 2024
in Malware, Mobile Security
Reading Time: 2 mins read
Android.Vo1d Infects android tv boxes world wide
Share on FacebookShare on Twitter

A newly discovered malware infection has raised alarm bells by affecting an estimated 1.3 million Android streaming devices running an open-source version across almost 200 countries.

The malware, dubbed “Android.Vo1d,” has successfully backdoored these Android-based boxes by inserting malicious code into their system storage areas, allowing for potential updates with additional malware via command-and-control servers at any time.

Scope and Impact

Security firm Doctor Web reported the widespread infection on Thursday, highlighting the extensive reach of the Android.Vo1d malware. The affected devices are operating systems based on the Android Open Source Project (AOSP), a version overseen by Google but distinct from the proprietary Android TV used by licensed device manufacturers.

Google representatives have confirmed that the infected devices are not running the official Android TV OS, emphasizing that these are “off-brand devices” without Play Protect certification. This certification process involves extensive testing to ensure quality and user safety. Confirm your TV is running Android TV OS by using the guide posted here.

Unknown Infection Vector

Despite their thorough understanding of the malware and its widespread impact, researchers at Doctor Web are still uncertain about the exact attack vector leading to these infections. They have proposed several possibilities:

  1. An intermediate malware exploiting operating system vulnerabilities to gain root privileges
  2. The use of unofficial firmware versions with built-in root access
  3. Outdated and vulnerable Android versions susceptible to remote code execution exploits
  4. Potential supply chain compromises, where devices may have been infected before reaching end-users

Affected Devices and Variants

The infection has been found on several TV box models, including:

You might also like

How Hackers Still Manage to Compromise MFA

Chinese Hackers Hijack Notepad++ Updates in 6-Month Supply Chain Campaign

Malicious Chrome Extensions Steal AI Data and Hijack Revenue in DarkSpectre Campaign

TV box modelDeclared firmware version
R4Android 7.1.2; R4 Build/NHG47K
TV BOXAndroid 12.1; TV BOX Build/NHG47K
KJ-SMART4KVIPAndroid 10.1; KJ-SMART4KVIP Build/NHG47K

Researchers have identified dozens of Android.Vo1d variants, each using different code and planting malware in slightly different storage areas. However, all variants achieve the same result: connecting to attacker-controlled servers and installing components that can deploy additional malware on command.

Infection Characteristics

The Android.Vo1d trojan modifies several system files and creates new ones to ensure persistence on infected devices. Key changes include:

  • Modification of the install-recovery.sh script
  • Alteration of the daemonsu file
  • Creation of new files: vo1d, wd, debuggerd, and debuggerd_real

These modifications allow the malware to anchor itself in the system and auto-launch during device reboots. The trojan’s main functionality is split between two components: vo1d (Android.Vo1d.1) and wd (Android.Vo1d.3), which work together to maintain the infection and execute commands from the control servers.

Geographic Distribution

android.Vo1d map en
Geographic Distribution of the Android.Vo1d infections

The infection has spread globally, with the highest number of cases detected in:

  • Brazil
  • Morocco
  • Pakistan
  • Saudi Arabia
  • Russia
  • Argentina
  • Ecuador
  • Tunisia
  • Malaysia
  • Algeria
  • Indonesia

Detection and Mitigation

Identifying infected devices can be challenging for less experienced users. Doctor Web recommends using their antivirus software for Android, which can detect all Vo1d variants and disinfect devices with root access. More technically inclined users can check for indicators of compromise provided by the security firm.

The incident also highlights the risks associated with using non-certified Android devices and emphasizes the importance of regular security updates and proper device vetting. As the investigation continues, it serves as a stark reminder of the ongoing challenges in securing the diverse ecosystem of Android-based devices in the market.

Previous Post

Unmasking TeslaCrypt: A Deep Dive into Ransomware Analysis and Prevention

Next Post

Supply Chain Pager Hack in Lebanon and Syria: Suspected Israeli Operation Targets Hezbollah

Paul

Paul

Editor and chief at ZeroSecurity. Expertise includes programming, malware analysis, and penetration testing. If you would like to write for ZeroSecurity, please click "Contact us" at the bottom of the page.

Recommended For You

How Hackers Still Manage to Compromise MFA

How Hackers Still Manage to Compromise MFA

March 6, 2026
Chinese Hackers Hijack Notepad++ Updates in 6-Month Supply Chain Campaign

Chinese Hackers Hijack Notepad++ Updates in 6-Month Supply Chain Campaign

February 6, 2026

Malicious Chrome Extensions Steal AI Data and Hijack Revenue in DarkSpectre Campaign

January 30, 2026

DoubleClickjacking – The Stealthy New Web Exploit Threatening User Security

January 1, 2025

BadBox Botnet Infects Over 190,000 Android Devices Worldwide

December 20, 2024

FBI Warns of HiatusRAT Targeting Network Devices Worldwide

December 18, 2024

Related News

Malicious Chrome Extensions Steal AI Data and Hijack Revenue in DarkSpectre Campaign

Malicious Chrome Extensions Steal AI Data and Hijack Revenue in DarkSpectre Campaign

January 30, 2026
KPMG Netherlands Listed as Victim by Nova Ransomware Group

KPMG Netherlands Listed as Victim by Nova Ransomware Group

January 24, 2026
RansomHouse Claims Breach of Key Apple Assembler Luxshare

RansomHouse Claims Breach of Key Apple Assembler Luxshare

January 20, 2026
ZeroSecurity - Information Security News

We cover the latest in technology news, Crypto, Artificial Intelligence, and the threat trends impacting these sectors.

Categories

Piracy

Tutorials

Programming

Malware Analysis

Downloads

  • Contact us
  • Press
  • Writers
  • Privacy Policy
  • Terms of Service

© 2026 ZeroSecurity, All Rights Reserved.

No Result
View All Result
  • Home
  • Security
    • Tools
  • Exploits
  • Data Breaches
  • Malware
  • Privacy
  • Mobile Security
  • Contact Us
    • Press
  • Privacy Policy

© 2026 ZeroSecurity, All Rights Reserved.

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.