Rootnik is an Android malware family centered on obtaining root privileges on infected devices and then abusing that access for persistent monetization and remote task execution. It masquerades as a benign utility application and uses staged payload delivery, encrypted assets, dynamic code loading, and multidex-based execution to conceal its main functionality. Analyses of Rootnik have documented native anti-analysis protections, including anti-debugging, anti-hooking, multi-process ptrace techniques, and checks for frameworks such as Xposed and Substrate, making reverse engineering more difficult.
Rootnik decrypts and loads secondary payloads at runtime, including DEX and JAR components, through mechanisms such as DexClassLoader and customized multidex installation. It gathers device information, retrieves additional encrypted components, and prepares a rooting workflow using multiple embedded exploit binaries, including publicly known Android privilege-escalation techniques and the MTK rooting scheme associated with the Dashi root tool. After successful privilege escalation, Rootnik executes scripts with elevated privileges to install hidden or disguised system applications into privileged locations, establishing durable control over the device.
Post-compromise, Rootnik functions as a remote-controlled Android threat capable of silently installing or uninstalling applications, installing system apps, downloading files, pushing notifications, creating home-screen shortcuts, and promoting applications and advertisements. Reporting has also associated it with pushing pornographic content. A hidden system component can act as the operational control service that fetches tasks from attacker infrastructure. Rootnik therefore combines loader, rooting, persistence, defense-evasion, and post-exploitation functionality in a single Android malware family.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
After investigating these executable files, I found that r3 is the MTK root scheme from the dashi root tool, the exploits method in r4 comes from one exploit(CVE-2013-6282) of the open source project android-rooting-tools... | From the analysis above, we can see that the rootnik malware is very powerful and uses very advanced anti-debugging and anti-hooking techniques to prevent reversing engineering... After successfully gaining root privileges on the device, the rootnik malware can perform a variety of malicious [actions], including app and ad promotion, pushing porn, creating shortcuts on the home screen, silent app installation, and pushing notifications.
...the exploit method in r2 is the CVE-2012-6422 which is a root exploit on Samsung Exynos. | From the analysis above, we can see that the rootnik malware is very powerful and uses very advanced anti-debugging and anti-hooking techniques to prevent reversing engineering... After successfully gaining root privileges on the device, the rootnik malware can perform a variety of malicious [actions], including app and ad promotion, pushing porn, creating shortcuts on the home screen, silent app installation, and pushing notifications.
18 distinct techniques documented for this family, organized by ATT&CK tactic.
The function hanleOriMiddle executes root exploits and some commands via a shell command... After successfully gaining root access, the script named psneuter.js is executed with super user privilege. ... Additionally, the other script named rsh is then executed via a shell command.
It includes four root exploits r1,r2,r3,r4... the exploits method in r4 comes from one exploit(CVE-2013-6282)... and the exploit method in r2 is the CVE-2012-6422... After successfully gaining root access, the script named psneuter.js is executed with super user privilege.
After successfully gaining root privileges on the device, the rootnik malware can perform several malicious behaviors, including app and ad promotion, pushing porn, creating shortcuts on the home screen, silent app installation, pushing notification, etc.
Understanding the packing mechanism takes a little bit of time, because all strings are obfuscated... The strings G9ugwFtlG1, .jwi, GIUh9JHGUIGIUHGokfewrofij58YV6UhYUF7gjhgv are found in a malware’s configuration class... De-obfuscation occurs through i.a()
The app disguises itself as an Android sync service... To avoid being caught by common users, these two apps have no icons on a victim’s device after being installed.
The content starts at offset 0x20 and ends at offset 0x1CDB in the file KK.bin... Its content is encrypted using the DES algorithm. In the function dxfile() the program decrypts the file contents... The payload is encrypted using the DES algorithm.
The malware disguises itself as a file helper app and then uses very advanced anti-debug and anti-hook techniques to prevent it from being reverse engineered.
This app runs in the background and does not have a launcher icon on the device... folder /data/data/com.web.sdfile/.rtt, which is a hidden system folder
The function GetActive is used to collect device information and send it to the remote server.
The malware disguises itself as a file helper app and then uses very advanced anti-debug and anti-hook techniques to prevent it from being reverse engineered.
The URL of remote server is http://grs[.]gowdsy[.]com:8092/active.do... The remote server has two domains. One is the main domain grs[.]gowdsy[.]com, and the other is backup domain grs[.]rogsob[.]com.
11 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned as prior Android malware that used the multidex loading scheme to load payloads as secondary DEX files.
Android malware disguised as a file helper app that gains root privileges using open-source Android root exploits and the MTK root scheme from the dashi root tool. It uses anti-debug and anti-hook protections, decrypts and loads a secondary dex payload via multidex, and then performs malicious actions including app/ad promotion, porn pushing, home-screen shortcut creation, silent app installation, and push notifications.
Android malware that dynamically loads multiple dex/jar payloads, downloads and decrypts additional components, roots infected devices using bundled exploits and scripts, installs privileged/system apps, communicates with C2 servers, and performs monetization and abuse activities such as silent app installs, ad/app promotion, porn pushing, shortcut creation, notifications, and file downloads.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.