Google engineer outlines the Android security team's efforts to curtail the Chamois botnet malware, which infected 20M+ devices at its peak in March 2018
Lily Hay Newman / Wired : Tweets: @wired Tweets: @wired : The malware family dubbed “Chamois” first cropped up in 2016 and hit an all-time high in 2018, infecting 20.8 million devices. Now the Android team has whittled that number back down to fewer than 2 million infections. Here's how they did it: http://www.wired.com/...
Context & Ripple Effects
Google has been publishing its Android malware numbers for years — it claimed to have cut Android malware in half in 2014 and by 2015 was scanning more than 6 billion installed apps daily. Chamois is the stress test of that machinery: first seen in 2016, it peaked at 20.8 million infected devices in March 2018 before the Android security team ground it down to under 2 million.
The Wired retrospective lands against a backdrop where the botnet problem hasn't gone away so much as moved: Doctor Web's Android.Vo1d botnet hit roughly 1.3 million AOSP-based TV boxes across nearly 200 countries in 2024, and Human Security later counted over a million infected Android TV streaming boxes, tablets, projectors, and car infotainment systems.
First-order effects
- Owners of the roughly 2 million devices still carrying Chamois remain exposed to its ad-fraud payload, while Google's Play-side scanning apparatus gets a proven, quantified win it can cite in enterprise and carrier security reviews.
- The takedown validates Google's scale-first defense model — continuous app scanning plus ecosystem telemetry — as the mechanism that actually retires a botnet at tens-of-millions scale.
Second-order effects
- Botnet operators respond by migrating to hardware Google's Play Protect doesn't govern: the Vo1d and Human Security outbreaks show cheap uncertified AOSP TV boxes becoming the preferred infection surface once phones harden.
- Ad-fraud economics stay the constant — from the Chinese ad firm monetizing 10 million infected phones to Chamois — meaning enforcement success shifts where fraudulent inventory is sourced rather than shrinking the fraud market itself.
Third-order effects
- If the pattern holds, Android security bifurcates into a well-defended certified-GMS phone fleet and an unmanaged long tail of AOSP set-top and embedded devices, making certification status a de facto security tier for buyers.
- Sustained platform-level takedowns push regulators and carriers toward treating botnet remediation as a shared-infrastructure obligation rather than each vendor's private cleanup job.
The trend: As Google's scanning infrastructure matures enough to crush phone botnets like Chamois, Android malware is migrating to unmanaged AOSP-based TV boxes and embedded devices outside Play Protect's reach.