A new variant of the Vo1d malware botnet has infected 1,590,299 Android TV devices in 226 countries, making them part of its anonymous proxy server networks.

A study by Xlab, which has been tracking the new campaign since last November, reports that the botnet peaked on January 14, 2025, and currently has 800,000 active bots.
In September last year, Dr. Web discovered 1.3 million devices in 200 countries that had been compromised by the Vo1d botnet. The recent report from XLab shows that the new version of the botnet is continuing its activities on a larger scale.
See also: Botnet targets Microsoft 365 Basic Auth
It was also observed that the botnet has evolved with advanced encryption (RSA + custom XXTEA), a resilient infrastructure powered by DGA, and improved capabilities that allow it to remain hidden.
A huge botnet
The Vo1d botnet is one of the largest in recent years, surpassing Bigpanzi, the original Mirai operation, and the botnet responsible for a 5.6 Tbps DDoS handled by Cloudflare last year.
According to the researchers, in February 2025, almost 25% of infections affected users in Brazil, followed by devices in South Africa (13.6%), Indonesia (10.5%), Argentina (5.3%), Thailand (3.4%), and China (3.1%).
The botnet is increasing its infections extremely quickly. For example, it reached 217,000 bots in India (from 3,900) in just three days.
Larger fluctuations suggest that botnet operators may be "renting" devices as proxy servers, which are typically used to conduct further illegal activity or engagement.
See also: Aquabotv3 botnet exploits vulnerability in Mitel phones
“We hypothesize that the phenomenon of “rapid increases followed by sharp decreases” can be attributed to the leasing of the botnet infrastructure Vo1d in specific regions to other groups. See how this “rent-and-return” cycle could work“:
Lease phase:
At the start of a lease, bots are diverted from the main Vo1d network to serve the tenant's operations. This diversion causes a sudden drop in Vo1d's infection count as bots are temporarily removed from its active pool.
Return phase:
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Once the lease period expires, the bots rejoin the Vo1d network. This rejoining leads to a rapid increase in the number of infections as the bots are reactivated under Vo1d's control.
This cyclical “rent and return” mechanism could explain the observed fluctuations in the scale of Vo1d at specific time points.”.
❖ Xlab
Regarding the command and control (C2) infrastructure, the researchers observed that it uses 32 domain generation algorithm (DGA) seeds to produce over 21,000 C2 domains.
C2 communication is protected by a 2048-bit RSA key, so even if researchers locate and register a C2 domain, they cannot issue commands to the bots.
Capabilities of the Vo1d botnet
The botnet turns compromised devices into proxy servers to facilitate illegal operations.
Infected devices relay malicious traffic for cybercriminals, hiding the origin of their activity and blending it with regular network traffic, thereby bypassing regional restrictions, security filtering, and other protections.
The Vo1d botnet also performs ad fraud. It falsifies user interactions by simulating ad clicks or views on video platforms to generate revenue for fraudulent advertisers.
The malware has specific plugins that automate interactions with ads and simulate human browsing behavior, as well as the Mzmess SDK, which distributes fraud tasks to different bots.
See also: New botnet exploits vulnerabilities in cameras and routers

Protection from the Vo1d botnet
Since the infection chain remains unknown, Android TV users are advised to implement multiple security measures. The most important is to purchase devices from trusted sellers and resellers. Otherwise, the device may contain the malware pre-loaded.
In addition, all firmware and security updates must be applied immediately to fix potential vulnerabilities that hackers can exploit.
It is also important to avoid downloading apps outside of Google Play.
Android TV devices should have remote access features disabled if they are not needed.
IoT devices should be on a different network than other valuable devices with sensitive data. Also, using strong passwords and changing them regularly is another way to protect yourself from the Vo1d Botnet. Botnet attacks often try to guess passwords, so using strong passwords and changing them regularly can help protect your accounts.
Finally, information security training can be particularly useful. Understanding how botnet attacks work can help you identify and avoid attacks.
Source: www.bleepingcomputer.com
