LSPatch is an Android application patching/instrumentation framework used to modify app behavior without changing the original application code, typically by loading additional modules or patches into the target app. In the provided reporting, threat actors used LSPatch to trojanize Android applications, including WhatsApp and Telegram X. In the WhatsApp supply-chain campaign documented by Doctor Web, attackers used LSPatch to load a malicious module (including a module named com.whatsHook.apk) into preinstalled WhatsApp on compromised low-end Android smartphones. That trojan, tracked by Doctor Web as Shibai and also referenced as Android.Clipper.31, hijacked WhatsApp update checks to fetch attacker-hosted APKs, searched messages for Tron and Ethereum wallet addresses, replaced them with attacker-controlled addresses while concealing the substitution from sender or recipient views, exfiltrated all WhatsApp chats, searched image folders for .jpg/.png/.jpeg files that could contain wallet mnemonic phrase screenshots, and sent device metadata to attacker infrastructure. Doctor Web reported the broader campaign affected devices from multiple Chinese manufacturers, used more than 60 C2 servers and about 30 distribution domains, and also involved roughly 40 modified apps such as Telegram, QR scanners, Trust Wallet, and MathWallet. In separate Doctor Web reporting on Android.Backdoor.Baohuo.1.origin, LSPatch was one of three observed methods used to implant the backdoor into trojanized Telegram X builds, where the malware stole credentials, chat data, SMS, contacts, clipboard contents, and enabled covert account manipulation. The content does not indicate that LSPatch itself is malware; rather, it is a legitimate framework abused by threat actors to embed malicious functionality into Android apps.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Android patching/instrumentation tool used to modify app behavior without changing original code; cited as used to embed Android.Clipper.31 into a WhatsApp modification.
Android app patching tool used by the attackers to dynamically load the Baohuo backdoor into Telegram X by applying a patch to the app’s DEX at runtime.
Android patching/modding framework used by the attackers to load a malicious module (com.whatsHook.apk) into legitimate apps without directly modifying the app code, enabling behaviors such as update hijacking and wallet-address replacement.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.