Rootnik
Rootnik is an Android malware family centered on obtaining root privileges on infected devices and then abusing that access for persistent monetization and remote task execution.
Rootnik
Family profile
Rootnik is an Android malware family centered on obtaining root privileges on infected devices and then abusing that access for persistent monetization and remote task execution. It masquerades as a benign utility application and uses staged payload delivery, encrypted assets, dynamic code loading, and multidex-based execution to conceal its main functionality. Analyses of Rootnik have documented native anti-analysis protections, including anti-debugging, anti-hooking, multi-process ptrace techniques, and checks for frameworks such as Xposed and Substrate, making reverse engineering more difficult.
Rootnik decrypts and loads secondary payloads at runtime, including DEX and JAR components, through mechanisms such as DexClassLoader and customized multidex installation. It gathers device information, retrieves additional encrypted components, and prepares a rooting workflow using multiple embedded exploit binaries, including publicly known Android privilege-escalation techniques and the MTK rooting scheme associated with the Dashi root tool. After successful privilege escalation, Rootnik executes scripts with elevated privileges to install hidden or disguised system applications into privileged locations, establishing durable control over the device.
Post-compromise, Rootnik functions as a remote-controlled Android threat capable of silently installing or uninstalling applications, installing system apps, downloading files, pushing notifications, creating home-screen shortcuts, and promoting applications and advertisements. Reporting has also associated it with pushing pornographic content. A hidden system component can act as the operational control service that fetches tasks from attacker infrastructure. Rootnik therefore combines loader, rooting, persistence, defense-evasion, and post-exploitation functionality in a single Android malware family.
Capabilities
- Defense Evasion
- Persistence
- Post Exploitation
- Privilege Escalation
- Reconnaissance
Samples
Recent samples
1 sandbox sample in the Derp library, newest 1 shown
Exploited software
Vulnerabilities linked to Rootnik
2 CVEsMITRE ATT&CK