Skip to content

Triada

Triada is a sophisticated Android malware family first documented in 2016 that evolved from a rooting trojan into a modular backdoor embedded in system images and, in later campaigns, directly into device firmware.

Profile source: Mallory opens in a new tab

Triada

Family profile

Triada is a sophisticated Android malware family first documented in 2016 that evolved from a rooting trojan into a modular backdoor embedded in system images and, in later campaigns, directly into device firmware. It has been repeatedly observed as preinstalled malware on counterfeit or low-cost Android devices and in trojanized third-party messaging app modifications, especially WhatsApp mods. Triada has also been linked to supply-chain compromise during manufacturing or distribution, allowing it to persist with system privileges and survive factory resets.

Triada’s architecture is modular and supports delivery of app-specific payloads from privileged contexts. Earlier variants focused on silently installing unwanted applications, displaying ads, replacing browser ads and links, and abusing rooted or system-level access to evade user controls. Later firmware-level variants infect the Android Zygote process through modified framework components, causing malicious code to be injected into every application launched on the device. This execution model gives Triada broad visibility into app data and enables payloads to run inside targeted applications.

Observed capabilities include downloading and executing additional modules, installing and uninstalling applications, blocking access to selected security or anti-fraud resources, intercepting or sending SMS messages, capturing transaction data from SMS-based in-app purchases, and exfiltrating device and application data over HTTP POST. Multiple variants have stolen credentials, authentication material, cookies, tokens, and active session data from messaging, social media, browser, and cryptocurrency applications. Documented modules have targeted Telegram, WhatsApp, LINE, Skype, TikTok, Instagram, Facebook, browsers, Google Play, Google Play Services, SMS apps, and phone components. Some variants can send arbitrary messages, delete messages or notifications, hijack browser links, operate infected devices as reverse proxies, and replace cryptocurrency wallet addresses in text fields, QR codes, and clipboard contents.

Triada has been described as one of the most advanced Android malware families because of its use of rooting, code injection, dynamic loading, privileged persistence, and app-process compromise. Security reporting has also linked Triada-like persistence techniques to later Android rootkit activity such as Operation NoVoice. Recent campaigns indicate continued active development, including adaptation to newer Android privilege restrictions through multi-stage loaders embedded in firmware. Triada has remained highly prevalent in mobile threat telemetry across multiple years, with preinstalled backdoor variants and trojanized messaging mods repeatedly ranking among the most frequently detected Android threats.

Capabilities

  • Credential Theft
  • Crypto Theft
  • Defense Evasion
  • Dll Sideloading
  • Exfiltration
  • Persistence
  • Privilege Escalation
  • Session Hijacking
  • Spoofing

Reported operators

Threat actors

1 named in public reporting
Vane Viper

"...redirect unsuspecting site users to ... malware, including an Android malware called Triada in one case."

MITRE ATT&CK

Triada in ATT&CK

44 distinct techniques

Reporting

Research mentioning Triada

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.