Leech is an Android malware family identified in mobile malware distribution chains as a downloader used to deliver more advanced payloads, notably Triada. It has been observed as part of an ecosystem of Android rooting malware that worked in concert with families such as Ztorg, Gorpo, and Iop to obtain unauthorized superuser privileges on vulnerable devices, install additional applications, and support large-scale malicious monetization activity. In documented xHelper infection chains, Leech appears as a late-stage downloader component that retrieves Triada together with exploits intended to gain root access on the victim device.
Its operational role is primarily to fetch and install follow-on malware rather than to serve as the final payload itself. Through this position in the chain, Leech contributes to compromise of Android devices by enabling installation of persistent system-level malware after privilege escalation. The broader campaigns in which it has appeared have targeted Android smartphones, especially devices and OS versions more susceptible to rooting, including some devices from Chinese manufacturers and, in some cases, devices reportedly shipped with malware already present in firmware. Once the downstream payload is installed, victims may face persistent compromise, stealthy system modification, additional malware deployment, and full attacker access to device data and functions.
The name Leech has also historically been attributed to a DOS-era virus associated with the Dark Avenger corpus, but the malware most clearly supported here is the Android downloader family used in mobile infection chains. In contemporary security usage, Leech is most relevant as an Android downloader linked to delivery of Triada and related rooted-device malware operations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct technique documented for this family, organized by ATT&CK tactic.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Final-stage downloader in xHelper’s chain that installs Triada.
Downloader module in the xHelper infection chain that retrieves Triada from command-and-control infrastructure.
Android rooting malware used in an advertising botnet that gains superuser privileges, installs apps, displays aggressive advertising, and helped distribute other malware including Triada.
Dark Avenger is believed to have authored the following viruses: ... and Leech.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.