"...redirect unsuspecting site users to ... malware, including an Android malware called Triada in one case."
Triada
Triada is a sophisticated modular Android malware family best known as a firmware-level backdoor and Trojan platform embedded into system images or preinstalled applications.
Profile source: Mallory opens in a new tabTriada
Family profile
Triada is a sophisticated modular Android malware family best known as a firmware-level backdoor and Trojan platform embedded into system images or preinstalled applications. First documented in 2016, it evolved from a root-enabled modular Trojan into a supply-chain threat capable of infecting devices during manufacturing or third-party firmware customization, including counterfeit and low-cost Android phones, tablets, TV boxes, and smart TVs. Triada has also appeared in trojanized apps and unofficial software distributions, including modified messaging clients and third-party app stores.
A defining characteristic of Triada is deep integration with core Android components. Multiple variants modify system libraries or framework elements and abuse the Zygote process so malicious code is injected into most or all app processes on the device. This architecture gives Triada broad visibility into application activity and enables stealth, persistence, and privilege inheritance that are unusual for mobile malware. Historical variants also obtained or leveraged superuser privileges, patched framework methods, hid their components from package and process listings, and loaded modules directly into memory to reduce forensic visibility.
Triada functions as a malware platform rather than a single-purpose implant. Confirmed capabilities across variants include downloading and executing additional payloads, silently installing or uninstalling applications, exfiltrating device and application data, intercepting SMS messages and one-time codes, modifying outgoing SMS used for paid transactions, browser URL spoofing and redirection, ad fraud, and abuse of legitimate apps such as Google Play to install attacker-selected software. More recent firmware-resident variants have also been documented stealing session material and account data from messaging, social media, browser, and cryptocurrency applications, turning devices into reverse proxies, and manipulating cryptocurrency wallet addresses inside targeted apps and clipboard flows.
Triada has been associated with several monetization schemes over time: SMS and in-app purchase fraud, premium-subscription fraud, silent app installs, intrusive advertising, click fraud, account abuse, session hijacking, residential proxying, and cryptocurrency theft. It has also served as a delivery vehicle for other Android malware families, including subscription Trojans, droppers, and persistent secondary implants. Some variants specifically targeted transaction flows in SMS-based purchases, while others targeted WhatsApp, Telegram, Instagram, LINE, Skype, TikTok, browsers, and crypto-wallet or exchange apps.
Distribution has occurred through multiple channels. High-confidence infection vectors include supply-chain compromise of firmware or OEM customization workflows, preinstalled malicious system apps, unofficial modified applications, and third-party Android app marketplaces. Triada-related activity has also been linked to broader Android supply-chain operations such as BADBOX and infrastructure overlap with Guerrilla, indicating that Triada techniques and operator ecosystems have influenced later preinstalled Android botnet and fraud operations.
Triada is widely regarded as one of the most technically advanced Android malware families of its era because of its modular design, process-wide injection, persistence in read-only system partitions, and ability to operate inside privileged or trusted system contexts. Its continued appearance in telemetry years after initial disclosure demonstrates the durability of the family and the ongoing risk posed by compromised Android firmware and preinstalled malware ecosystems.
Capabilities
- Credential Theft
- Crypto Theft
- Defense Evasion
- Exfiltration
- Persistence
- Post Exploitation
- Privilege Escalation
- Process Injection
- Session Hijacking
- Spoofing
Reported operators
Threat actors
1 named in public reportingMITRE ATT&CK
Triada in ATT&CK
54 distinct techniquesTechniques
54 techniquesReporting
Research mentioning Triada
Lemon Group’s Cybercriminal Businesses Built on Preinfected Devices | TrendAI (US)
Researchers reported a large Android supply-chain compromise in which devices from more than 50 brands were shipped with malware embedded in firmware, allowing attackers to control phones before users installed any apps. Trend Micro said the operation, attributed to Lemon Group, implanted Guerrilla malware through a tampered zygote-related library and used a core plugin called Sloth to fetch modules for SMS interception, proxying, cookie theft, WhatsApp abuse, ad fraud, and silent app installation. Telemetry and actor-hosted data indicated activity across more than 180 countries, hundreds of thousands of mobile numbers used for OTP requests, and millions of potentially affected devices, with the business later rebranded in part from Lemon SMS to Durian Cloud SMS while keeping backend infrastructure. The findings echo earlier reporting on Triada, an Android malware family that evolved from a rooting trojan into a preinstalled system-image backdoor embedded in framework components. Google previously said Triada abused privileged contexts such as System UI and Google Play to execute code, monitor foreground apps, replace ads, and install applications so they appeared to come from Google Play, and that infections were inserted into device images during production by a third party using the names Yehuo or Blazefire. Trend Micro said the newer Guerrilla campaign showed infrastructure overlap with Triada operators, suggesting a continuing ecosystem of firmware-level Android compromise monetized through fraud, silent installs, and persistent device backdoors.
Google Play Apps Use Stealth Loaders to Deliver Anatsa Banking Malware
Kaspersky reported that Android attacks involving malware, adware, and unwanted software fell to 1,996,823 in Q2 2026 from 2,676,328 in the previous quarter, but banking malware remained the leading threat. Trojan-Banker detections accounted for 30.77% of malicious applications, and researchers identified more than 304,000 malicious installation packages, including 93,574 mobile banking Trojan packages and 570 mobile ransomware packages. The report also noted that some banking Trojans were reclassified as droppers as attackers increasingly packed payloads, contributing to growth in Trojan-Dropper detections. The quarter’s most notable campaigns included malicious loaders distributed through Google Play. Researchers said a trojanized PDF reader was used to deliver the Anatsa banking Trojan, while the Cleanova app relied on SDK telemetry to selectively activate malicious functionality and evade app store review. Kaspersky also said Triada variants remained prominent, Mamont banking Trojan variants rose sharply and appear to be under active development, and attacks tied to some pre-installed Trojans declined, likely because vendors patched affected firmware.
IT threat evolution in Q2 2026. Mobile statistics - Malware News - Malware Analysis, News and Indicators
Q2 2026 Android threat landscape | Securelist
Toll fraud malware: How an Android application can drain your wallet | Microsoft Security Blog
Several Android malware families, including Joker, MobOk, Vesub, and GriftHorse, were found fraudulently enrolling victims in paid mobile subscription services by abusing device permissions, intercepting SMS confirmation codes, and hiding billing steps inside deceptive app workflows. Researchers said the malware used techniques such as notification access, invisible webviews, fake login prompts, and anti-fraud evasion to complete sign-ups without clear user consent, turning infected phones into tools for recurring premium-service charges. The campaigns were distributed through multiple channels, including Google Play, unofficial app stores, preinstalled software, and trojanized popular applications. Joker operated as a staged downloader that could tamper with confirmation flows, MobOk added CAPTCHA bypass capabilities and was often linked to delivery by Triada, Vesub spread through fake apps from unofficial sources, and GriftHorse variants relied on misleading subscription pages and hidden recurring billing terms. Victim telemetry covering January 2021 through March 2022 showed Russia as the most affected country overall, with MobOk identified as the most prevalent family among the subscription trojans reviewed.
Cyble - Fake Income Tax Application Targets Indian Taxpayers
Researchers identified an Android malware app named iMobile that impersonates India’s Income Tax Department and targets Indian taxpayers through phishing, harvesting sensitive data including PAN, Aadhaar, bank account information, debit card details, and internet banking credentials. The app also seeks extensive dangerous permissions and attempts to set itself as the device’s default SMS application, giving it the ability to read, receive, and send text messages while monitoring phone state and usage data. Analysis showed the stolen banking and internet-banking information was uploaded to the command-and-control endpoint jsig.quicksytes[.]com/MC/NN180521/mc.php, and the sample used string deobfuscation and hardcoded artifacts including an Indian mobile number. The campaign reflects a broader mobile threat pattern documented in MITRE ATT&CK T1636.004, where malicious apps abuse SMS access to intercept messages, including one-time passcodes and transaction alerts, to support credential theft, financial fraud, and account takeover.
Everyone sees not what they want to see | Securelist
Kaspersky reported that a Triada Android malware module was hijacking mobile web traffic through browser URL spoofing after gaining superuser privileges on infected devices. Detected as Backdoor.AndroidOS.Triada.p, Backdoor.AndroidOS.Triada.o, and Backdoor.AndroidOS.Triada.q, the module injected a DLL into browser processes and then downloaded URL-rewrite rules from its command-and-control infrastructure to silently alter where victims were sent online. The activity was observed redirecting users by changing default search engines and browser home pages, but the same mechanism could also be used to send victims visiting banking sites to phishing pages controlled by attackers. Kaspersky said the campaign affected 247 users during the observation period and found no indication that the operation was slowing, underscoring the risk of persistent mobile malware capable of covert traffic manipulation.