Dwphon is an Android Trojan/downloader and preinstalled malware family reported by Kaspersky. It has been described as a loader built into system applications responsible for over-the-air (OTA) updates, and as malware that came preinstalled on certain devices. Kaspersky telemetry placed it among prevalent mobile malware in 2024, including verdicts such as Trojan-Downloader.AndroidOS.Dwphon.a. The available content associates Dwphon with supply-chain style compromise of Android devices rather than user-initiated installation, but does not provide further high-confidence technical details on payloads, command-and-control, specific targeted industries, or indicators of compromise beyond its integration into OTA-related system apps and its preinstalled presence on affected devices.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct technique documented for this family, organized by ATT&CK tactic.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Previously documented Android loader embedded into system/OTA-related apps; referenced as an analogous technique to Keenadu loader placement in system apps.
Android downloader trojan referenced as pre-installed on devices in some cases; appears in top detections for Q2 2025.
Загрузчик, встроенный в системные приложения OTA-обновлений Android-устройств как пример предустановленного вредоносного ПО в прошивках.
Trojan downloader found preinstalled on certain Android devices.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.