Dendroid is an Android HTTP remote access trojan marketed in underground forums as a stealthy mobile malware kit with a PHP-based control panel and an APK binder for trojanizing legitimate applications. It has been associated with the Android.Dendoroid detection name and is regarded as part of the early wave of commoditized Android crimeware derived from or influenced by earlier Android RAT ecosystems such as AndroRAT.
Dendroid provides broad remote surveillance and device-control functionality on infected Android devices. Reported capabilities include intercepting SMS messages; sending and blocking SMS traffic; recording audio through the device microphone; recording calls; taking photos and videos; collecting photos, browser history, bookmarks, and accounts stored on the device; opening applications and web pages; placing calls; deleting call logs; changing its command-and-control server; and launching HTTP flood attacks. It also supports deceptive credential collection by displaying dialog boxes that prompt users for passwords.
A notable delivery and evasion feature is its ability to be bound to legitimate Android applications before installation, enabling trojanized app distribution while remaining relatively transparent to the user. This positions Dendroid as both a surveillance tool and a flexible post-compromise implant for cybercriminal operators. Its feature set spans credential theft, data exfiltration, device monitoring, and active abuse of victim communications, making it relevant to both financially motivated abuse and broader espionage-style mobile intrusion activity.
Dendroid targets the Android platform.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
7 distinct techniques documented for this family, organized by ATT&CK tactic.
Anubis can exfiltrate files encrypted with the ransomware module from the device and can modify external storage. BusyGasper can collect images stored on the device and browser history. CHEMISTGAMES can collect files from the filesystem and account information from Google Chrome.
18 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Android malware that can capture photos and record videos.
Android remote access trojan that can be bound to legitimate applications before installation.
Android malware that can prompt users for passwords via fake dialog boxes.
Android remote access trojan that steals photos, browser data, and stored accounts.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.