Triada is a sophisticated modular Android malware family best known as a firmware-level backdoor and Trojan platform embedded into system images or preinstalled applications. First documented in 2016, it evolved from a root-enabled modular Trojan into a supply-chain threat capable of infecting devices during manufacturing or third-party firmware customization, including counterfeit and low-cost Android phones, tablets, TV boxes, and smart TVs. Triada has also appeared in trojanized apps and unofficial software distributions, including modified messaging clients and third-party app stores.
A defining characteristic of Triada is deep integration with core Android components. Multiple variants modify system libraries or framework elements and abuse the Zygote process so malicious code is injected into most or all app processes on the device. This architecture gives Triada broad visibility into application activity and enables stealth, persistence, and privilege inheritance that are unusual for mobile malware. Historical variants also obtained or leveraged superuser privileges, patched framework methods, hid their components from package and process listings, and loaded modules directly into memory to reduce forensic visibility.
Triada functions as a malware platform rather than a single-purpose implant. Confirmed capabilities across variants include downloading and executing additional payloads, silently installing or uninstalling applications, exfiltrating device and application data, intercepting SMS messages and one-time codes, modifying outgoing SMS used for paid transactions, browser URL spoofing and redirection, ad fraud, and abuse of legitimate apps such as Google Play to install attacker-selected software. More recent firmware-resident variants have also been documented stealing session material and account data from messaging, social media, browser, and cryptocurrency applications, turning devices into reverse proxies, and manipulating cryptocurrency wallet addresses inside targeted apps and clipboard flows.
Triada has been associated with several monetization schemes over time: SMS and in-app purchase fraud, premium-subscription fraud, silent app installs, intrusive advertising, click fraud, account abuse, session hijacking, residential proxying, and cryptocurrency theft. It has also served as a delivery vehicle for other Android malware families, including subscription Trojans, droppers, and persistent secondary implants. Some variants specifically targeted transaction flows in SMS-based purchases, while others targeted WhatsApp, Telegram, Instagram, LINE, Skype, TikTok, browsers, and crypto-wallet or exchange apps.
Distribution has occurred through multiple channels. High-confidence infection vectors include supply-chain compromise of firmware or OEM customization workflows, preinstalled malicious system apps, unofficial modified applications, and third-party Android app marketplaces. Triada-related activity has also been linked to broader Android supply-chain operations such as BADBOX and infrastructure overlap with Guerrilla, indicating that Triada techniques and operator ecosystems have influenced later preinstalled Android botnet and fraud operations.
Triada is widely regarded as one of the most technically advanced Android malware families of its era because of its modular design, process-wide injection, persistence in read-only system partitions, and ability to operate inside privileged or trusted system contexts. Its continued appearance in telemetry years after initial disclosure demonstrates the durability of the family and the ongoing risk posed by compromised Android firmware and preinstalled malware ecosystems.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
"...redirect unsuspecting site users to ... malware, including an Android malware called Triada in one case."
27 distinct techniques documented for this family, organized by ATT&CK tactic.
In time, threat actors turned to reflashing and silent installation as techniques for malicious activities... In 2021, we were studying detections of the SMS PVA mobile botnet fueled by compromised mobile supply chain attacks when we discovered the botnet and the operations of the threat actors.
Finally, because of the backdoor’s connection to C2 servers on BADBOX-infected smartphones, tablets, and CTV boxes, new apps or code can be remotely installed by the threat actors without the device owner’s permission.
The backdoor also injected code that allowed it to use the Google Play app to download and install apps of the attackers’ choice.
Users of smartphones who do not receive security updates are less fortunate: in outdated versions of the OS, the malware is capable of not only loading additional apps, but installing them on the system partition.
Once the app is launched, the malware gathers unique device identifiers...
If classes.dex is deleted from memory, it’s immediately restored, underscoring the persistence of the threat.
The T95 device examined by the Satori team, upon booting up, immediately injected the com.jar library into process memory... The classes.dex file created by the decryption of classes.png is injected into the above launcher process.
classes.png, the filename of which suggests an image file, is actually an encrypted file that, when decrypted, turns into classes.dex.
The T95 device examined by the Satori team, upon booting up, immediately injected the com.jar library into process memory... The classes.dex file created by the decryption of classes.png is injected into the above launcher process.
If these files were updated earlier than the last response was received, the Trojan deletes these files
After that, the modules are removed from the disk, i.e. they only remain in device memory
When the app starts, the payload is decrypted and launched. In this case, it is located in a long string in the app code.
If classes.dex is deleted from memory, it’s immediately restored, underscoring the persistence of the threat.
At some point between the manufacturing of these products and their delivery to resellers... a firmware backdoor—based on Triada malware—gets installed.
The Trojan substitutes the function to hide its modules from this list... running services... running applications... installed packages
the Trojan substitutes standard methods from Android Framework with methods implemented in libconfigpppl.so
For one, it used XOR encoding and ZIP files to encrypt communications.
115 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
52 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Android malware previously reported as implanted into devices; in this reference it is discussed as having overlapping infrastructure or network flow with Guerrilla operators, suggesting possible cooperation between the groups.
Android malware family appearing prominently in Q2 2026 detection rankings, represented by multiple backdoor and trojan variants among the most frequently detected mobile threats.
Android malware family appearing in multiple backdoor and trojan variants and prominently represented in the quarter's top mobile malware detections.
Android malware family appearing in both backdoor and trojan detections, with multiple variants among the most frequently detected mobile malware in the quarter.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.