Vo1d is a large-scale Android botnet targeting consumer media-streaming devices, particularly unofficial Android TV boxes sold under numerous brands and model names. First publicly disclosed in September 2024, it affected approximately 1.3 million devices across roughly 200 countries. Follow-up research in March 2025 estimated an infected population of approximately 1.6 million devices across 226 countries and regions.
Vo1d incorporates a residential-proxy plugin called Popa that turns compromised devices into exit nodes for third-party internet traffic without their owners' knowledge or consent. Popa provides the networking and tunneling layer rather than the complete malware payload. It registers devices with remote control infrastructure, obtains relay assignments, maintains encrypted connections, and opens communication tunnels on demand. This allows third-party traffic to emerge from victims' residential internet connections.
The Popa component shares proxy infrastructure with SDKs embedded in consumer applications, including streaming applications and VPN software. Technical analysis has established that the Popa plugin used on Vo1d-infected Android devices and the Neunative SDK bundled with RoboVPN are different clients of the same proxy backend; this infrastructure overlap does not establish that the Windows application is itself Vo1d.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
16 distinct techniques documented for this family, organized by ATT&CK tactic.
The malware was capable of running arbitrary executables and downloading and installing any APKs.
The C2 infrastructure responds to the registration by assigning the device a specific proxy role. The response is a structured data object containing a proxy host and port that the device will use to route criminal traffic through the victim's home internet connection.
Within 2.17 seconds of powering on — before any user touches the remote — the device contacts ota.triplesai[.]com:8080 over HTTP. The traffic mimics a legitimate over-the-air firmware update check, but the payload contains the device's complete fingerprint.
A consumer projector was generating DNS queries on a precise ~65-second cycle... The domain: .o.fecebbbk[.]xyz... The DNS responses are configured with a deliberate 60-second TTL... every infected device worldwide automatically follows within 60 seconds.
Once active, it silently enrolls the device as a residential proxy node — routing criminal internet traffic through the victim's home IP address without their knowledge or consent.
Bundled in the same installer, registered as a NuGet dependency, and activated whenever the VPN is not connected, is Neunative: a residential-proxy SDK that turns the user's machine into an exit node for third-party traffic.
The hostnames in peer_servers are rotating front domains. For a single fleet the director returns both sN.viki-play[.]com:6000 and sN.star-layer[.]com:6000 ... The sN identifier and IP are the stable node identity. The domain is disposable.
Xlab disclosed the following domains as part of their command and control (C2)... the Popa plugin retrieves the address of an operational backend server... In the case of Vo1d, the main botnet infects and manages devices, while the Popa module can be later added...
113 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
29 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware / Outils # JarService (loader) zhima (other) BADBOX (botnet) Vo1d (other)
Referenced only as a comparison point for large-scale abuse of connected Android devices.
Mentioned only as part of Kaspersky detection verdict naming, not analyzed as a malware family in the article.
A larger botnet of which Popa/NetNut is described as a plugin component; it targets unofficial Android-based TV boxes distributed with pirated streaming apps.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.