"...redirect unsuspecting site users to ... malware, including an Android malware called Triada in one case."
Triada
Triada is a sophisticated Android malware family first documented in 2016 that evolved from a rooting trojan into a modular backdoor embedded in system images and, in later campaigns, directly into device firmware.
Profile source: Mallory opens in a new tabTriada
Family profile
Triada is a sophisticated Android malware family first documented in 2016 that evolved from a rooting trojan into a modular backdoor embedded in system images and, in later campaigns, directly into device firmware. It has been repeatedly observed as preinstalled malware on counterfeit or low-cost Android devices and in trojanized third-party messaging app modifications, especially WhatsApp mods. Triada has also been linked to supply-chain compromise during manufacturing or distribution, allowing it to persist with system privileges and survive factory resets.
Triada’s architecture is modular and supports delivery of app-specific payloads from privileged contexts. Earlier variants focused on silently installing unwanted applications, displaying ads, replacing browser ads and links, and abusing rooted or system-level access to evade user controls. Later firmware-level variants infect the Android Zygote process through modified framework components, causing malicious code to be injected into every application launched on the device. This execution model gives Triada broad visibility into app data and enables payloads to run inside targeted applications.
Observed capabilities include downloading and executing additional modules, installing and uninstalling applications, blocking access to selected security or anti-fraud resources, intercepting or sending SMS messages, capturing transaction data from SMS-based in-app purchases, and exfiltrating device and application data over HTTP POST. Multiple variants have stolen credentials, authentication material, cookies, tokens, and active session data from messaging, social media, browser, and cryptocurrency applications. Documented modules have targeted Telegram, WhatsApp, LINE, Skype, TikTok, Instagram, Facebook, browsers, Google Play, Google Play Services, SMS apps, and phone components. Some variants can send arbitrary messages, delete messages or notifications, hijack browser links, operate infected devices as reverse proxies, and replace cryptocurrency wallet addresses in text fields, QR codes, and clipboard contents.
Triada has been described as one of the most advanced Android malware families because of its use of rooting, code injection, dynamic loading, privileged persistence, and app-process compromise. Security reporting has also linked Triada-like persistence techniques to later Android rootkit activity such as Operation NoVoice. Recent campaigns indicate continued active development, including adaptation to newer Android privilege restrictions through multi-stage loaders embedded in firmware. Triada has remained highly prevalent in mobile threat telemetry across multiple years, with preinstalled backdoor variants and trojanized messaging mods repeatedly ranking among the most frequently detected Android threats.
Capabilities
- Credential Theft
- Crypto Theft
- Defense Evasion
- Dll Sideloading
- Exfiltration
- Persistence
- Privilege Escalation
- Session Hijacking
- Spoofing
Reported operators
Threat actors
1 named in public reportingMITRE ATT&CK
Triada in ATT&CK
44 distinct techniquesTechniques
44 techniquesReporting
Research mentioning Triada
Google Play Apps Use Stealth Loaders to Deliver Anatsa Banking Malware
Kaspersky reported that Android attacks involving malware, adware, and unwanted software fell to 1,996,823 in Q2 2026 from 2,676,328 in the previous quarter, but banking malware remained the leading threat. Trojan-Banker detections accounted for 30.77% of malicious applications, and researchers identified more than 304,000 malicious installation packages, including 93,574 mobile banking Trojan packages and 570 mobile ransomware packages. The report also noted that some banking Trojans were reclassified as droppers as attackers increasingly packed payloads, contributing to growth in Trojan-Dropper detections. The quarter’s most notable campaigns included malicious loaders distributed through Google Play. Researchers said a trojanized PDF reader was used to deliver the Anatsa banking Trojan, while the Cleanova app relied on SDK telemetry to selectively activate malicious functionality and evade app store review. Kaspersky also said Triada variants remained prominent, Mamont banking Trojan variants rose sharply and appear to be under active development, and attacks tied to some pre-installed Trojans declined, likely because vendors patched affected firmware.