SecuriDropper is an Android Dropper-as-a-Service family designed to install malicious payloads in a way that bypasses Android 13 Restricted Settings protections. It uses the session-based PackageInstaller workflow normally associated with official app marketplace installations, causing the operating system to treat the delivered payload more like a store-installed application than a conventional sideloaded app. This enables follow-on malware to request sensitive permissions, including Accessibility-related privileges, that Android 13 was intended to restrict for sideloaded software.
SecuriDropper commonly requests storage and package-installation related permissions, checks whether a target payload is already present, and either launches the installed malware directly or guides the victim through a reinstall flow with localized prompts. It has been observed masquerading as legitimate Android applications, including social and productivity themed apps, and serving as the delivery mechanism for both spyware and banking trojans. Documented payloads include SpyNote and Ermac. In these campaigns, the dropper is used to deploy malware that can steal sensitive information, abuse Accessibility services, and support broader fraud or surveillance objectives.
Observed distribution channels include phishing websites, deceptive websites, third-party platforms, and Discord-based lures. SecuriDropper is therefore best understood as a specialized Android loader/dropper ecosystem focused on defeating platform security controls so that downstream malware can obtain high-risk permissions and execute post-installation malicious activity on victim devices.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
6 distinct techniques documented for this family, organized by ATT&CK tactic.
Upon launching the payload, a request surfaces, this time seeking user consent to enable AccessibilityService – the frequently exploited permission Restricted Settings was intended to deny to these apps.
SecuriDropper ... bypasses Restricted Settings using the method we identified back in 2022 ... this family uses a different Android API to install the new payload, mimicking the process used by marketplaces to install new applications. In this way, the Operating System cannot differentiate between an application installed by a dropper and a marketplace and allows the payload to bypass the "Restricted Settings" feature in Android 13.
5 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Android dropper cited as background for the same session-based sideloading technique used by the analyzed GodFather dropper.
Android dropper referenced as prior malware that used a session-based installer technique to bypass protections and install payloads.
Android dropper family offered as Dropper-as-a-Service that uses a session-based package installation method to bypass Android 13 Restricted Settings and install secondary payloads such as spyware and banking trojans while enabling abuse of Accessibility permissions.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.