/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Google engineer outlines the Android security team's efforts to curtail the Chamois botnet malware, which infected 20M+ devices at its peak in March 2018

Lily Hay Newman / Wired : Tweets: @wired Tweets: @wired : The malware family dubbed “Chamois” first cropped up in 2016 and hit an all-time high in 2018, infecting 20.8 million devices. Now the Android team has whittled that number back down to fewer than 2 million infections. Here's how they did it: http://www.wired.com/...

Wired Lily Hay Newman

Context & Ripple Effects

Google has been publishing its Android malware numbers for years — it claimed to have cut Android malware in half in 2014 and by 2015 was scanning more than 6 billion installed apps daily. Chamois is the stress test of that machinery: first seen in 2016, it peaked at 20.8 million infected devices in March 2018 before the Android security team ground it down to under 2 million.

The Wired retrospective lands against a backdrop where the botnet problem hasn't gone away so much as moved: Doctor Web's Android.Vo1d botnet hit roughly 1.3 million AOSP-based TV boxes across nearly 200 countries in 2024, and Human Security later counted over a million infected Android TV streaming boxes, tablets, projectors, and car infotainment systems.

First-order effects

  • Owners of the roughly 2 million devices still carrying Chamois remain exposed to its ad-fraud payload, while Google's Play-side scanning apparatus gets a proven, quantified win it can cite in enterprise and carrier security reviews.
  • The takedown validates Google's scale-first defense model — continuous app scanning plus ecosystem telemetry — as the mechanism that actually retires a botnet at tens-of-millions scale.

Second-order effects

  • Botnet operators respond by migrating to hardware Google's Play Protect doesn't govern: the Vo1d and Human Security outbreaks show cheap uncertified AOSP TV boxes becoming the preferred infection surface once phones harden.
  • Ad-fraud economics stay the constant — from the Chinese ad firm monetizing 10 million infected phones to Chamois — meaning enforcement success shifts where fraudulent inventory is sourced rather than shrinking the fraud market itself.

Third-order effects

  • If the pattern holds, Android security bifurcates into a well-defended certified-GMS phone fleet and an unmanaged long tail of AOSP set-top and embedded devices, making certification status a de facto security tier for buyers.
  • Sustained platform-level takedowns push regulators and carriers toward treating botnet remediation as a shared-infrastructure obligation rather than each vendor's private cleanup job.

The trend: As Google's scanning infrastructure matures enough to crush phone botnets like Chamois, Android malware is migrating to unmanaged AOSP-based TV boxes and embedded devices outside Play Protect's reach.