Long Live The Vo1d Botnet: New Variant Hits 1.6 Million TV Globally
· Published 28/02/2025 10:35 · Modified 28/02/2025 11:10
Essential information
- Published
- 28/02/2025 10:35
- Modified
- 28/02/2025 11:10
- Tags
- 2025-02-28 android tv botnet proxy network set-top box vo1d
- Related entities
- 48 observables, 1 intrusion sets (apt), 20 techniques (mitre), 3 malware, 20 others
Description
The Vo1d botnet has infected 1.6 million Android TV devices across 200+ countries, posing a significant cybersecurity threat. This new variant demonstrates enhanced stealth and resilience, utilizing RSA encryption, DGA-based infrastructure, and a modified XXTEA algorithm. The botnet's scale and capabilities surpass previous major attacks, potentially enabling devastating DDoS attacks or unauthorized content broadcasting. Analysis reveals a sophisticated multi-component system including downloaders, backdoors, and modular malware for proxy services and ad fraud. The botnet's rapid growth and evasion techniques highlight the urgent need for improved security measures in smart TV devices and set-top boxes.
Related entities
Vulnerabilities, IOCs, intrusion sets, MITRE techniques and other entities referenced in this report.
Observables (48)
69.28.62.6169.28.62.6069.28.62.5269.28.62.5169.28.62.5069.28.62.4969.28.62.4869.28.62.4169.28.62.4269.28.62.3969.28.62.3838.61.8.3338.61.8.3138.61.8.1438.61.8.1338.61.8.1238.61.8.1138.46.218.3938.46.218.3838.46.218.3638.46.218.37156.236.118.48156.236.118.27128.1.71.243https://dcsdkos.dc16888888.com/sdkbinhttps://dcsdkos.dc16888888.com/reportcompbinhttps://dcsdk.100ulife.com/sdkbinhttps://dcsdk.100ulife.com/reportcompbinhttp://task.moyu88.xyz/cpc/api/xml?productId=0http://task.moyu88.xyz/cpc/api/taskhttp://ssl87362.com:9999http://task.moyu88.xyz/cpc/api/proxy/originhttp://jaguar-distributor.syslogcollector.com:12000/v1/agent/ctrlhttp://dcsdkos.dc16888888.com/sdkbinhttp://dcsdk.100ulife.com/sdkbinhttp://dcsdkos.dc16888888.com/reportcompbinhttp://dcsdk.100ulife.com/reportcompbinhttp://csskkjw.com/s3/b7027626http://adstat.ziyemy.shop:3389update.ad3g.comwowokeys.comssl87362.comspiritlib.cyoucsskkjw.comcsok997.comconannt.comcatmore23.com2940637fafa.com
Intrusion sets (APT) (1)
-
AlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 12:38 · Modified 21/12/2025 12:38
Techniques (MITRE) (20)
-
Dynamic Resolution
-
Masquerade Task or Service
-
Stage Capabilities
-
Software Packing
-
Query Registry
-
Encrypted Channel
-
System Network Configuration Discovery
-
Shared Modules
-
System Information Discovery
-
Ingress Tool Transfer
-
Application Layer Protocol
-
Web Service
-
Process Injection
-
Masquerading
-
Deobfuscate/Decode Files or Information
-
Data Encoding
-
Obfuscated Files or Information
-
Modify Registry
-
Data Obfuscation
-
Command and Scripting Interpreter
Malware (3)
Others (20)
- British Indian Ocean Territory
- Iraq
- South Africa
- India
- China
- Argentina
- Thailand
- Malaysia
- Indonesia
- Germany
- Morocco
- Philippines
- Ecuador
- Mexico
- Pakistan
- Brazil
- United States of America
- Russian Federation
- Media
- Telecommunications