Skip to content

Triada

Triada is a sophisticated modular Android malware family best known as a firmware-level backdoor and Trojan platform embedded into system images or preinstalled applications.

Profile source: Mallory opens in a new tab

Triada

Family profile

Triada is a sophisticated modular Android malware family best known as a firmware-level backdoor and Trojan platform embedded into system images or preinstalled applications. First documented in 2016, it evolved from a root-enabled modular Trojan into a supply-chain threat capable of infecting devices during manufacturing or third-party firmware customization, including counterfeit and low-cost Android phones, tablets, TV boxes, and smart TVs. Triada has also appeared in trojanized apps and unofficial software distributions, including modified messaging clients and third-party app stores.

A defining characteristic of Triada is deep integration with core Android components. Multiple variants modify system libraries or framework elements and abuse the Zygote process so malicious code is injected into most or all app processes on the device. This architecture gives Triada broad visibility into application activity and enables stealth, persistence, and privilege inheritance that are unusual for mobile malware. Historical variants also obtained or leveraged superuser privileges, patched framework methods, hid their components from package and process listings, and loaded modules directly into memory to reduce forensic visibility.

Triada functions as a malware platform rather than a single-purpose implant. Confirmed capabilities across variants include downloading and executing additional payloads, silently installing or uninstalling applications, exfiltrating device and application data, intercepting SMS messages and one-time codes, modifying outgoing SMS used for paid transactions, browser URL spoofing and redirection, ad fraud, and abuse of legitimate apps such as Google Play to install attacker-selected software. More recent firmware-resident variants have also been documented stealing session material and account data from messaging, social media, browser, and cryptocurrency applications, turning devices into reverse proxies, and manipulating cryptocurrency wallet addresses inside targeted apps and clipboard flows.

Triada has been associated with several monetization schemes over time: SMS and in-app purchase fraud, premium-subscription fraud, silent app installs, intrusive advertising, click fraud, account abuse, session hijacking, residential proxying, and cryptocurrency theft. It has also served as a delivery vehicle for other Android malware families, including subscription Trojans, droppers, and persistent secondary implants. Some variants specifically targeted transaction flows in SMS-based purchases, while others targeted WhatsApp, Telegram, Instagram, LINE, Skype, TikTok, browsers, and crypto-wallet or exchange apps.

Distribution has occurred through multiple channels. High-confidence infection vectors include supply-chain compromise of firmware or OEM customization workflows, preinstalled malicious system apps, unofficial modified applications, and third-party Android app marketplaces. Triada-related activity has also been linked to broader Android supply-chain operations such as BADBOX and infrastructure overlap with Guerrilla, indicating that Triada techniques and operator ecosystems have influenced later preinstalled Android botnet and fraud operations.

Triada is widely regarded as one of the most technically advanced Android malware families of its era because of its modular design, process-wide injection, persistence in read-only system partitions, and ability to operate inside privileged or trusted system contexts. Its continued appearance in telemetry years after initial disclosure demonstrates the durability of the family and the ongoing risk posed by compromised Android firmware and preinstalled malware ecosystems.

Capabilities

  • Credential Theft
  • Crypto Theft
  • Defense Evasion
  • Exfiltration
  • Persistence
  • Post Exploitation
  • Privilege Escalation
  • Process Injection
  • Session Hijacking
  • Spoofing

Reported operators

Threat actors

1 named in public reporting
Vane Viper

"...redirect unsuspecting site users to ... malware, including an Android malware called Triada in one case."

MITRE ATT&CK

Triada in ATT&CK

54 distinct techniques

Techniques

54 techniques
T1071 Application Layer Protocol T1195 Supply Chain Compromise T1547 Boot or Logon Autostart Execution T1036 Masquerading T1059 Command and Scripting Interpreter T1055 Process Injection T1105 Ingress Tool Transfer T1542 Pre-OS Boot T1542.001 System Firmware T1528 Steal Application Access Token T1072 Software Deployment Tools T1001 Data Obfuscation T1082 System Information Discovery T1106 Native API T1518 Software Discovery T1041 Exfiltration Over C2 Channel T1601 Modify System Image T1574 Hijack Execution Flow T1068 Exploitation for Privilege Escalation T1070 Indicator Removal T1140 Deobfuscate/Decode Files or Information T1204 User Execution T1070.004 File Deletion T1574.006 Dynamic Linker Hijacking T1620 Reflective Code Loading T1564 Hide Artifacts T1189 Drive-by Compromise T1027.007 Dynamic API Resolution T1222 File and Directory Permissions Modification T1562 Impair Defenses T1037 Boot or Logon Initialization Scripts T1059.007 JavaScript T1027 Obfuscated Files or Information T1056 Input Capture T1115 Clipboard Data T1071.001 Web Protocols T1555 Credentials from Password Stores T1057 Process Discovery T1129 Shared Modules T1556 Modify Authentication Process T1539 Steal Web Session Cookie T1027.013 Encrypted/Encoded File T1095 Non-Application Layer Protocol T1090 Proxy T1498 Network Denial of Service T1566 Phishing T1568 Dynamic Resolution T1547.006 Kernel Modules and Extensions T1005 Data from Local System T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol T1574.001 DLL T1548 Abuse Elevation Control Mechanism T1114 Email Collection T1204.002 Malicious File

Reporting

Research mentioning Triada

Aug 20
Trendai Security

Lemon Group’s Cybercriminal Businesses Built on Preinfected Devices | TrendAI (US)

Researchers reported a large Android supply-chain compromise in which devices from more than 50 brands were shipped with malware embedded in firmware, allowing attackers to control phones before users installed any apps. Trend Micro said the operation, attributed to Lemon Group, implanted Guerrilla malware through a tampered zygote-related library and used a core plugin called Sloth to fetch modules for SMS interception, proxying, cookie theft, WhatsApp abuse, ad fraud, and silent app installation. Telemetry and actor-hosted data indicated activity across more than 180 countries, hundreds of thousands of mobile numbers used for OTP requests, and millions of potentially affected devices, with the business later rebranded in part from Lemon SMS to Durian Cloud SMS while keeping backend infrastructure. The findings echo earlier reporting on Triada, an Android malware family that evolved from a rooting trojan into a preinstalled system-image backdoor embedded in framework components. Google previously said Triada abused privileged contexts such as System UI and Google Play to execute code, monitor foreground apps, replace ads, and install applications so they appeared to come from Google Play, and that infections were inserted into device images during production by a third party using the names Yehuo or Blazefire. Trend Micro said the newer Guerrilla campaign showed infrastructure overlap with Triada operators, suggesting a continuing ecosystem of firmware-level Android compromise monetized through fraud, silent installs, and persistent device backdoors.

Aug 10
Cyber Security News

Google Play Apps Use Stealth Loaders to Deliver Anatsa Banking Malware

Kaspersky reported that Android attacks involving malware, adware, and unwanted software fell to 1,996,823 in Q2 2026 from 2,676,328 in the previous quarter, but banking malware remained the leading threat. Trojan-Banker detections accounted for 30.77% of malicious applications, and researchers identified more than 304,000 malicious installation packages, including 93,574 mobile banking Trojan packages and 570 mobile ransomware packages. The report also noted that some banking Trojans were reclassified as droppers as attackers increasingly packed payloads, contributing to growth in Trojan-Dropper detections. The quarter’s most notable campaigns included malicious loaders distributed through Google Play. Researchers said a trojanized PDF reader was used to deliver the Anatsa banking Trojan, while the Cleanova app relied on SDK telemetry to selectively activate malicious functionality and evade app store review. Kaspersky also said Triada variants remained prominent, Mamont banking Trojan variants rose sharply and appear to be under active development, and attacks tied to some pre-installed Trojans declined, likely because vendors patched affected firmware.

Aug 10
Malware News

IT threat evolution in Q2 2026. Mobile statistics - Malware News - Malware Analysis, News and Indicators

Aug 10
Securelist

Q2 2026 Android threat landscape | Securelist

Jun 30
Microsoft General

Toll fraud malware: How an Android application can drain your wallet | Microsoft Security Blog

Several Android malware families, including Joker, MobOk, Vesub, and GriftHorse, were found fraudulently enrolling victims in paid mobile subscription services by abusing device permissions, intercepting SMS confirmation codes, and hiding billing steps inside deceptive app workflows. Researchers said the malware used techniques such as notification access, invisible webviews, fake login prompts, and anti-fraud evasion to complete sign-ups without clear user consent, turning infected phones into tools for recurring premium-service charges. The campaigns were distributed through multiple channels, including Google Play, unofficial app stores, preinstalled software, and trojanized popular applications. Joker operated as a staged downloader that could tamper with confirmation flows, MobOk added CAPTCHA bypass capabilities and was often linked to delivery by Triada, Vesub spread through fake apps from unofficial sources, and GriftHorse variants relied on misleading subscription pages and hidden recurring billing terms. Victim telemetry covering January 2021 through March 2022 showed Russia as the most affected country overall, with MobOk identified as the most prevalent family among the subscription trojans reviewed.

Sep 7
Cyble Blog Historic

Cyble - Fake Income Tax Application Targets Indian Taxpayers

Researchers identified an Android malware app named iMobile that impersonates India’s Income Tax Department and targets Indian taxpayers through phishing, harvesting sensitive data including PAN, Aadhaar, bank account information, debit card details, and internet banking credentials. The app also seeks extensive dangerous permissions and attempts to set itself as the device’s default SMS application, giving it the ability to read, receive, and send text messages while monitoring phone state and usage data. Analysis showed the stolen banking and internet-banking information was uploaded to the command-and-control endpoint jsig.quicksytes[.]com/MC/NN180521/mc.php, and the sample used string deobfuscation and hardcoded artifacts including an Indian mobile number. The campaign reflects a broader mobile threat pattern documented in MITRE ATT&CK T1636.004, where malicious apps abuse SMS access to intercept messages, including one-time passcodes and transaction alerts, to support credential theft, financial fraud, and account takeover.

May 13
Securelist

Everyone sees not what they want to see | Securelist

Kaspersky reported that a Triada Android malware module was hijacking mobile web traffic through browser URL spoofing after gaining superuser privileges on infected devices. Detected as Backdoor.AndroidOS.Triada.p, Backdoor.AndroidOS.Triada.o, and Backdoor.AndroidOS.Triada.q, the module injected a DLL into browser processes and then downloaded URL-rewrite rules from its command-and-control infrastructure to silently alter where victims were sent online. The activity was observed redirecting users by changing default search engines and browser home pages, but the same mechanism could also be used to send victims visiting banking sites to phishing pages controlled by attackers. Kaspersky said the campaign affected 247 users during the observation period and found no indication that the operation was slowing, underscoring the risk of persistent mobile malware capable of covert traffic manipulation.

May 13
Securelist

The Trojan subscribers Joker, MobOk, Vesub and GriftHorse | Securelist

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.