Lemon Group is a cybercriminal threat actor associated with a large-scale Android mobile supply-chain compromise and monetization ecosystem. The group is known for preinfecting Android devices and firmware with Guerrilla malware, using tampered system components to achieve early execution and broad process-level reach on compromised devices. Parts of the operation were later rebranded as Durian Cloud SMS while retaining the same backend infrastructure. Lemon Group has also been identified as one of the groups folded into the broader BADBOX 2.0 ecosystem. The actor’s activity has been assessed as active since at least 2018. Its implant architecture used a modified zygote-related library to load a downloader into core Android processes, enabling delivery of additional plugins across app processes in a manner comparable to global process injection. More recent loader variants reportedly adopted fileless techniques. Researchers also observed overlap with Triada-linked infrastructure and assessed that Lemon Group and Triada operators likely cooperated at some point. Lemon Group’s operations centered on criminal monetization of infected devices through multiple plugins and services. Guerrilla’s plugin set supported SMS interception for one-time-password capture and phone-verification abuse, residential or reverse proxy enablement through compromised devices, theft of cookies and social-media account data, WhatsApp session hijacking and message abuse, ad fraud, and silent installation or removal of applications. The SMS interception capability supported an SMS PVA business that provided customers with phone numbers and OTP functionality for major online platforms. Additional plugins harvested Facebook-related cookies and profile data, abused compromised accounts for marketing activity, displayed intrusive advertisements, and executed silent app-management tasks under command-and-control direction. The operation had global reach, with infected devices observed in more than 180 countries and telemetry indicating hundreds of thousands of mobile numbers used for OTP requests. More than 50 mobile device brands and over 50 firmware images were identified as carrying initial loaders associated with the activity. Lemon Group has been linked to illicit monetization through OTP abuse, proxy services, ad fraud, and account hijacking, with possible secondary information theft for resale. Its dominant profile is that of a financially motivated cybercriminal actor focused on supply-chain compromise of Android devices at scale.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
18 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 malware families attributed to this actor across reporting.
11 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A mobile supply-chain threat actor operating a criminal enterprise built on preinfected Android devices. The group implants Guerrilla malware and multiple plugins to intercept SMS/OTPs, run proxy services, steal cookies and account data, hijack WhatsApp sessions, push ads, and silently install or uninstall apps for monetization and fraud.
One of multiple actor groups involved in BADBOX 2.0 ad fraud/residential proxy abuse ecosystem.
Operates a mobile malware ecosystem with plugins for SMS interception and OTP theft, reverse proxying via infected Android devices, Facebook cookie theft and account hijacking, WhatsApp session abuse for spam, ad injection, and silent app installation. The operation also supports SMS PVA and proxy monetization services and uses compromised accounts/devices for overseas marketing and infrastructure abuse.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.