Last year, the Lemon Group was found to be engaged in ad fraud — 50 different brands of Android devices were infected with the Guerrilla Trojan.
Reported operators
Threat actors
1 named in public reportingMITRE ATT&CK
Guerrilla in ATT&CK
1 distinct techniquesTechniques
1 techniqueReporting
Research mentioning Guerrilla
Lemon Group’s Cybercriminal Businesses Built on Preinfected Devices | TrendAI (US)
Researchers reported a large Android supply-chain compromise in which devices from more than 50 brands were shipped with malware embedded in firmware, allowing attackers to control phones before users installed any apps. Trend Micro said the operation, attributed to Lemon Group, implanted Guerrilla malware through a tampered zygote-related library and used a core plugin called Sloth to fetch modules for SMS interception, proxying, cookie theft, WhatsApp abuse, ad fraud, and silent app installation. Telemetry and actor-hosted data indicated activity across more than 180 countries, hundreds of thousands of mobile numbers used for OTP requests, and millions of potentially affected devices, with the business later rebranded in part from Lemon SMS to Durian Cloud SMS while keeping backend infrastructure. The findings echo earlier reporting on Triada, an Android malware family that evolved from a rooting trojan into a preinstalled system-image backdoor embedded in framework components. Google previously said Triada abused privileged contexts such as System UI and Google Play to execute code, monitor foreground apps, replace ads, and install applications so they appeared to come from Google Play, and that infections were inserted into device images during production by a third party using the names Yehuo or Blazefire. Trend Micro said the newer Guerrilla campaign showed infrastructure overlap with Triada operators, suggesting a continuing ecosystem of firmware-level Android compromise monetized through fraud, silent installs, and persistent device backdoors.