A sophisticated botnet operation has compromised 1.6 million Android TV devices across 226 nations, leveraging advanced domain generation algorithms and cryptographic evasion techniques to create the largest known IoT threat since the 2016 Mirai attacks.
Dubbed Vo1d, this operation represents a paradigm shift in large-scale device hijacking through its multi-layered infrastructure and novel ASR-XXTEA encryption variant.
The campaign began on November 28, 2024, when researchers detected IP 38.46.218.36 distributing the jddx ELF loader using Bigpanzi-style string obfuscation.
Loader Components: Initial downloaders like s63 establish TLS 1.3 connections to hardcoded C2s (ssl8rrs2.com:55600) using RSA-2048/OAEP padding for key exchange. Each session negotiates unique XXTEA-128 keys through:
Payload Obfuscation: Second-stage modules like ts01 employ arithmetic shift right (ASR) modifications to XXTEA. This thwarts standard decryption tools while maintaining backward compatibility.
Persistence Mechanisms: Final payloads deploy DexLoader APKs (MD5: 68ec86a761233798142a6f483995f7e9) masquerading as Google Play Services, using XML attribute spoofing.
Vo1d’s infrastructure employs 258 DGA seeds generating 21,120 domains across .com/.net/.top TLDs, with 32-character patterns like z{mask}2940637fafa.com.
“On December 8, 2024, while monitoring 135 million Bot IPs through a DGA C2 sinkhole, we noticed an unusually low infection count in China, only a few dozen cases despite the country’s vast number of Android TV devices”, reads XLab’s report.
Infection rates show alarming volatility in developing markets:
India:
China:
Researchers attribute these fluctuations to a “botnet leasing” model where criminal groups temporarily acquire device clusters for DDoS (≤5.6 Tbps) or proxy services.
Despite these efforts, 800,000+ devices remain active as of February 28, 2025, with new Mzmess plugins enabling:
The HUD breach demonstrates Vo1d’s media manipulation capabilities, using forced AV sync protocols to override HDMI-CEC controls.
With 1.6 million devices capable of generating 1.2 petabits/sec of malicious traffic, the botnet represents an existential threat to CDN providers (Cloudflare, Akamai), broadcast infrastructure (ATSC 3.0 networks), and smart city IoT grids.
This evolving crisis underscores the urgent need for mandatory SBOM disclosures in IoT supply chains and international cooperation to dismantle the Vo1d infrastructure.
With infection rates growing exponentially in South Asia and MENA regions, the window for effective countermeasures is rapidly closing.
Collect Threat Intelligence on the Latest Malware and Phishing Attacks with ANY.RUN TI Lookup -> Try for free
Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…
Hackers are making some phishing pages harder to track by changing the code delivered to…
A cyber incident reportedly forced a British power plant to halt operations for about four…
Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…
TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…
A fake student resume is being used to place a remote-access tool on researchers’ Windows…