Skip to content

Reported operators

Threat actors

1 named in public reporting
Lemon Group

Last year, the Lemon Group was found to be engaged in ad fraud — 50 different brands of Android devices were infected with the Guerrilla Trojan.

MITRE ATT&CK

Guerrilla in ATT&CK

1 distinct techniques

Reporting

Research mentioning Guerrilla

Aug 20
Trendai Security

Lemon Group’s Cybercriminal Businesses Built on Preinfected Devices | TrendAI (US)

Researchers reported a large Android supply-chain compromise in which devices from more than 50 brands were shipped with malware embedded in firmware, allowing attackers to control phones before users installed any apps. Trend Micro said the operation, attributed to Lemon Group, implanted Guerrilla malware through a tampered zygote-related library and used a core plugin called Sloth to fetch modules for SMS interception, proxying, cookie theft, WhatsApp abuse, ad fraud, and silent app installation. Telemetry and actor-hosted data indicated activity across more than 180 countries, hundreds of thousands of mobile numbers used for OTP requests, and millions of potentially affected devices, with the business later rebranded in part from Lemon SMS to Durian Cloud SMS while keeping backend infrastructure. The findings echo earlier reporting on Triada, an Android malware family that evolved from a rooting trojan into a preinstalled system-image backdoor embedded in framework components. Google previously said Triada abused privileged contexts such as System UI and Google Play to execute code, monitor foreground apps, replace ads, and install applications so they appeared to come from Google Play, and that infections were inserted into device images during production by a third party using the names Yehuo or Blazefire. Trend Micro said the newer Guerrilla campaign showed infrastructure overlap with Triada operators, suggesting a continuing ecosystem of firmware-level Android compromise monetized through fraud, silent installs, and persistent device backdoors.

Jun 6
Google Security

Google Online Security Blog: PHA Family Highlights: Triada

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.