Beware The Vo1d

1.3 Million Android TV Boxes Infected with Vo1d Malware, Warns Doctor Web

A new malware called Vo1d has infected nearly 1.3 million Android-based TV boxes worldwide, compromising the security of users in 197 countries. The backdoor malware can download and install third-party software without users’ knowledge, and most infections have been detected in Brazil, Morocco, Pakistan, and other countries.

Malware Details

Vo1d replaces the “/system/bin/debuggerd” daemon file and introduces two new files, “/system/xbin/vo1d” and “/system/xbin/wd,” containing malicious code. It targets TV models such as KJ-SMART4KVIP, R4, and TV BOX, which run outdated Android versions. The malware operates by starting the “wd” module and downloading executables from a command-and-control server.

Infection Method

The source of the infection is unknown, but it may have involved prior compromise or the use of unofficial firmware with built-in root access. The malware disguises itself as the “vold” program, substituting the lowercase “l” with a number “1” in the filename.

Google Response

Google notes that the infected devices were not Play Protect certified, as they used source code from the Android Open Source Project without undergoing the necessary security and compatibility tests. Users can check if their devices are Play Protect certified on the Android TV website.

Mitigations

To protect against Vo1d, users should update their TV boxes to the latest Android version and avoid using unofficial firmware. Manufacturers should prioritize security and use up-to-date OS versions to prevent similar attacks.

Conclusion

The Vo1d malware highlights the importance of keeping devices up-to-date and using official firmware to prevent infections. Users should be cautious when using non-certified devices and manufacturers should prioritize security to protect their customers.

(Citation: The Hacker News, “Beware: New Vo1d Malware Infects 1.3 Million Android-based TV Boxes Worldwide,” September 12, 2024, by Ravie Lakshmanan)

Scroll to Top