Hadoken Security Group is a cybercriminal malware developer and operator associated with Android banking malware, most notably Xenomorph, and with Android droppers including Gymdrop and BugDrop. The group has publicly claimed ownership of Xenomorph and related tooling and has shown signs of promoting its malware commercially, including indications of movement toward a malware-as-a-service model. The actor’s operations center on Android device compromise and banking fraud. Xenomorph is an Android banking trojan that evolved from overlay-based credential theft into a more capable platform with Accessibility Services abuse, remote-action support, notification and SMS interception, cookie theft, and a full Automated Transfer System framework. These capabilities enable end-to-end fraud automation, including credential capture, MFA interception, balance checking, transaction initiation, and funds transfer. Reported command support has included app enumeration, injection control, SMS handling, SOCKS proxy functionality, app termination, self-removal, USSD execution, call forwarding, and ATS execution. Hadoken-linked delivery methods have included distribution through Android droppers and binder-style packaging of malicious payloads with legitimate applications. Xenomorph has been delivered via Gymdrop, BugDrop, and Zombinder-based campaigns, including lures masquerading as benign mobile software and fake security-related updates. BugDrop in particular was assessed as an in-development Android dropper tied to Xenomorph delivery. It requested Accessibility permissions, communicated over TOR, downloaded Xenomorph payloads, and appeared to reuse code from the Brox or MasterFred malware family. Its development suggested an attempt to abuse Android session-based installation mechanisms to bypass newer Android restrictions on sideloaded apps obtaining Accessibility privileges. Targeting has focused heavily on banking and financial institutions, with later expansion to a much broader set of financial targets including cryptocurrency wallets. Earlier targeting prominently included institutions in Spain, Portugal, and Italy, with later additions in Belgium and Canada. The scale and technical progression of Xenomorph indicate a mature Android fraud operation emphasizing credential theft, session abuse, and automated financial theft rather than espionage.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
15 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 malware families attributed to this actor across reporting.
109 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Developer/operator behind the Xenomorph Android banking trojan, evolving it with ATS capabilities, overlay attacks, keylogging, cookie theft, and MaaS-style commercialization while testing multiple distribution methods including GymDrop, BugDrop, and Zombinder.
Android cybercrime group associated with Xenomorph, Gymdrop, and the in-development BugDrop dropper. The group is developing Android droppers to distribute banking malware and is experimenting with session-based installation methods to bypass Android 13 restricted settings and obtain Accessibility Services privileges for malware deployment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.