Lemon Group is an Android-focused cybercriminal operation associated with large-scale mobile-device monetization and abuse. The group has also operated under the name Durian Cloud SMS after rebranding in 2022 while retaining the same backend infrastructure. It has been linked to plugin-based Android malware used to intercept SMS messages and one-time passwords, abuse compromised devices as proxy nodes, hijack social-media and messaging accounts, conduct ad fraud, and silently install or remove applications on infected devices. Observed Lemon Group tooling includes SMS interception components that capture OTPs from major online platforms, proxy modules that expose infected phones’ network connectivity for operator use, cookie-stealing components targeting Facebook-related applications, WhatsApp session-hijacking functionality, intrusive advertising modules, and silent installation plugins controlled by command-and-control tasking. The group has used stolen Facebook cookies and profile data, including account-associated information, to take over accounts and support marketing abuse. Compromised WhatsApp sessions have also been used to send unwanted messages. The operation appears financially motivated, with capabilities aligned to mobile fraud enablement and account abuse at scale. Its infrastructure and victimology indicate broad international reach, with infected Android devices observed across more than 180 countries. Known associated names include Lemon Group and Durian Cloud SMS.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
8 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
One of multiple actor groups involved in BADBOX 2.0 ad fraud/residential proxy abuse ecosystem.
Operates a mobile malware ecosystem with plugins for SMS interception and OTP theft, reverse proxying via infected Android devices, Facebook cookie theft and account hijacking, WhatsApp session abuse for spam, ad injection, and silent app installation. The operation also supports SMS PVA and proxy monetization services and uses compromised accounts/devices for overseas marketing and infrastructure abuse.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.