Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
We found that the group turned it into a criminal enterprise and established the network since at least 2018. We identified the malware as Guerrilla and deployed by the threat actor group we named “Lemon Group”... Following reports of phones being compromised with Guerrilla malware, we purchased a phone and extracted the ROM image for forensic analysis.
16 distinct techniques documented for this family, organized by ATT&CK tactic.
In time, threat actors turned to reflashing and silent installation as techniques for malicious activities... In 2021, we were studying detections of the SMS PVA mobile botnet fueled by compromised mobile supply chain attacks when we discovered the botnet and the operations of the threat actors.
This injected code will decrypt a DEX file from the data section and load it into memory.
The more recent versions of the loaders use fileless techniques when downloading and injecting other payloads.
The implant is a tampered zygote dependency library that will load a downloader into a zygote process... every time other app processes are forked from the zygote, it would also be tampered.
SMS plugin: Capable of intercepting received SMS and read specific messages such as one-time passwords (OTP) from various platforms
The WhatsApp plugin is used to hijack WhatsApp sessions to send unwanted messages.
We identified the infrastructure of their backend, including the malicious plugins and command and control (C&C) servers... Pivoting on http response of the domain led us to identify other Lemon Group C&C domains
11 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A preinstalled Android malware framework implanted in device firmware and zygote-related components. It tampered with system libraries to inject code, decrypt and load DEX payloads in memory, and download additional plugins for SMS interception, OTP theft, proxying, cookie theft, WhatsApp hijacking, ad fraud, and silent app installation/uninstallation.
Referenced only as a historical comparison for Android library or firmware compromise techniques similar to those seen in BADBOX.
An Android Trojan associated with large-scale ad fraud on preinfected devices across multiple brands.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.