InsighthubNews
  • Home
  • World News
  • Politics
  • Celebrity
  • Environment
  • Business
  • Technology
  • Crypto
  • Sports
  • Gaming
Reading: New Vo1d malware infects 1.3 million Android-based TV boxes worldwide
Share
Font ResizerAa
InsighthubNewsInsighthubNews
Search
  • Home
  • World News
  • Politics
  • Celebrity
  • Environment
  • Business
  • Technology
  • Crypto
  • Sports
  • Gaming
© 2024 All Rights Reserved | Powered by Insighthub News
InsighthubNews > Technology > New Vo1d malware infects 1.3 million Android-based TV boxes worldwide
Technology

New Vo1d malware infects 1.3 million Android-based TV boxes worldwide

September 15, 2024 4 Min Read
Share
New Vo1d malware infects 1.3 million Android-based TV boxes worldwide
SHARE

Approximately 1.3 million Android-based TV boxes running an older version of the operating system, owned by users in 197 countries, have been infected with a new malware called Vo1d (aka Void).

“This is a backdoor capable of placing components in the system’s storage area and covertly downloading and installing third-party software at the attacker’s command,” Russian antivirus vendor Doctor Web said in a report published today.

The majority of infections have been confirmed in Brazil, Morocco, Pakistan, Saudi Arabia, Argentina, Russia, Tunisia, Ecuador, Malaysia, Algeria and Indonesia.

The source of the infection is currently unknown, but it is suspected to be related to previous compromises that allowed users to gain root privileges, or the use of unofficial firmware versions with built-in root access.

The following TV models are eligible for the campaign:

  • KJ-SMART4KVIP (Android 10.1; KJ-SMART4KVIP Build/NHG47K)
  • R4 (Android 7.1.2; R4 build/NHG47K)
  • TV BOX (Android 12.1, TV BOX Build/NHG47K)

The attack involves replacing the “/system/bin/debuggerd” daemon file (moving the original to a backup file called “debuggerd_real”) and introducing two new files (“/system/xbin/vo1d” and “/system/xbin/wd”) that contain malicious code and run simultaneously.

“Prior to Android 8.0, crashes were handled by the debuggerd and debuggerd64 daemons,” Google says in the Android documentation. “Starting with Android 8.0, crash_dump32 and crash_dump64 are generated as needed.”

Two different files that shipped as part of the Android operating system – install-recovery.sh and daemonsu – were modified as part of the campaign to launch the ‘wd’ module and trigger the malware’s execution.

“It appears that the Trojan’s creators tried to disguise one of its components as the system program ‘/system/bin/vold’, giving it a similar name: ‘vo1d’ (replacing the lowercase letter ‘l’ with the number ‘1’),” Doctor Web said.

See also  New PIXHELL attack exploits LCD screen noise to steal data from isolated computers

The “vo1d” payload then launches “wd” to ensure it is persistent, downloads and runs executables as instructed by the command and control (C2) server, and monitors designated directories and installs APK files it finds there.

“Unfortunately, it is not uncommon for low-cost device manufacturers to take older OS versions and market them as more current versions to make them appear more attractive,” the company said.

update

Google told The Hacker News that the affected TV models are not Play Protect certified Android devices and likely use source code from the Android Open Source Project code repository. Here is the company’s full statement:

“These non-branded devices found to be infected are Play Protect Certified Android DevicesIf a device is not Play Protect Certified, Google does not keep a record of its security and compatibility test results. Play Protect Certified Android devices have undergone extensive testing to ensure quality and user safety. To find out if your device has Android TV OS and is Play Protect Certified, Android TV website We provide an up-to-date list of partners. These steps Check if your device is Play Protect Certified.”

Share This Article
Twitter Copy Link
Previous Article Get up to 75% off Horizon Zero Dawn and other PlayStation classics Get up to 75% off Horizon Zero Dawn and other PlayStation classics
Next Article Yucaipa residents fight back against mega-warehouse proposal Yucaipa residents fight back against mega-warehouse proposal
Leave a comment Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Latest News

The Solution is Cyber ​​Hygiene

The Solution is Cyber ​​Hygiene

Cybersecurity in healthcare has never been more urgent. As the…

September 19, 2024
mm

Enterprise LLM API: A top choice for powering LLM applications in 2024

Some big recent news stories have escalated the race for…

September 19, 2024
Authentication Bypass

GitLab fixes critical SAML authentication bypass vulnerability in CE and EE editions

GitLab has released a patch to address a critical flaw…

September 19, 2024
Chinese engineer indicted in US for years of cyberespionage targeting NASA and military

Chinese engineer indicted in US for years of cyberespionage targeting NASA and military

A Chinese national has been indicted in the United States…

September 19, 2024
IoT Botnet

New “Raptor Train” IoT Botnet Compromises Over 200,000 Devices Worldwide

Cybersecurity researchers have discovered a never-before-seen botnet made up of…

September 18, 2024

You Might Also Like

MISTPEN Malware
Technology

North Korean Hackers Target Energy and Aerospace Industries with New MISTPEN Malware

4 Min Read
TrickMo Android Trojan
Technology

TrickMo Android Trojan exploits accessibility services to carry out banking fraud on devices

5 Min Read
insighthubnews
Technology

EAGLE: Exploring the design space of multimodal large-scale language models with a mixture of encoders

19 Min Read
Goodbye to Phishing
Technology

A must-have to combat credential theft

6 Min Read
InsighthubNews
InsighthubNews

Welcome to InsighthubNews, your reliable source for the latest updates and in-depth insights from around the globe. We are dedicated to bringing you up-to-the-minute news and analysis on the most pressing issues and developments shaping the world today.

  • Home
  • Celebrity
  • Environment
  • Business
  • Crypto
  • Home
  • World News
  • Politics
  • Celebrity
  • Environment
  • Business
  • Technology
  • Crypto
  • Sports
  • Gaming
  • World News
  • Politics
  • Technology
  • Sports
  • Gaming
  • About us
  • Contact Us
  • Disclaimer
  • Privacy Policy
  • Terms of Service
  • About us
  • Contact Us
  • Disclaimer
  • Privacy Policy
  • Terms of Service

© 2024 All Rights Reserved | Powered by Insighthub News

Welcome Back!

Sign in to your account

Lost your password?