Triada is an Android malware threat actor and associated Trojan ecosystem known for deeply embedded, firmware-level compromise of Android devices, particularly counterfeit or tampered smartphones in the supply chain. The operation is notable for preinstalling malicious components into system partitions and abusing the Android Zygote process so that malware code is inherited by nearly every application launched on the device. This architecture gives Triada broad access to app data, permissions, and runtime behavior, enabling persistent and stealthy compromise at scale. Recent Triada activity has used malicious system framework components and native libraries to register code inside core Android processes, deploy modular payloads into app contexts, and maintain a backdoor capable of downloading and executing additional modules. Observed modules support cryptocurrency theft, SMS fraud, arbitrary application installation and removal, browser traffic manipulation, reverse proxying, and theft of credentials, cookies, tokens, and session material from major messaging, social media, browser, and financial applications. Triada has also been observed intercepting and sending messages, deleting selected messages, suppressing notifications, replacing links, manipulating clipboard and wallet-address fields, and redirecting or blocking selected network lookups to evade anti-fraud controls. The malware’s targeting has included cryptocurrency applications, Telegram, WhatsApp, Instagram, LINE, Skype, TikTok, browsers, SMS applications, Google Play, Google Play Services, and phone applications. Its capabilities include account takeover, session hijacking, credential and token theft, premium-SMS abuse, silent app deployment, and use of infected devices as reverse proxies. Telemetry has shown infections worldwide, with notable concentrations in Russia, the United Kingdom, the Netherlands, Germany, and Brazil. Triada has code continuity with older Android Triada variants and has been linked by code and infrastructure overlap to other malicious mobile activity. Chinese-language developer comments have been observed in the malware, supporting assessment of a Chinese nexus. Infrastructure overlap has also been observed between Triada operators and the Guerrilla mobile malware operation, suggesting at least some historical cooperation or shared infrastructure. The actor’s dominant motivation is financial, reflected in cryptocurrency theft, fraud, monetization of compromised devices, and abuse of victim communications and network resources.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
40 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A separate threat actor/operator set associated here through overlapping C2 infrastructure and network flow with Lemon Group, suggesting possible cooperation or shared operations.
A supply-chain-style Android malware operation embedding Triada into counterfeit device firmware before sale, then using Zygote-level infection and modular payloads to steal cryptocurrency, hijack messaging and social media accounts, intercept SMS, replace browser links, install/uninstall apps, block anti-fraud domains, and turn devices into reverse proxies.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.