Trend Micro reported that the Lemon Group, later rebranded as Durian Cloud SMS, operated a large cybercriminal ecosystem built on preinfected Android devices. The malware framework used multiple plugins to monetize compromised phones through SMS interception, proxy services, account hijacking, ad fraud, and silent app installation directed by command-and-control servers. Researchers said the malware could capture one-time passcodes from services including WhatsApp, Facebook, QQ, Line, Tinder, and JingDong, dump Facebook cookies and profile data, hijack WhatsApp sessions, and remotely install or remove APKs without user awareness.
Trend Micro said the operators removed some Lemon branding after earlier public exposure but kept the same infrastructure in place under the Durian Cloud SMS name. Monitoring tied the operation to more than 490,000 mobile numbers used for OTP requests, and infected devices were observed in over 180 countries. The most affected countries included the United States, Mexico, Indonesia, Thailand, Russia, South Africa, India, Angola, the Philippines, and Argentina, indicating a globally distributed mobile fraud and account-compromise operation.

TTPs, infrastructure, and targeting history in one profile.
3 events from the most recent confirmed update back to the earliest known activity.
Trend Micro reported that the operation used multiple Android malware plugins for SMS interception, proxy services, account hijacking, ad fraud, and silent app installation. The company said it observed more than 490,000 mobile numbers used for OTP requests and infected devices in over 180 countries.
In May 2022, the operators reportedly removed some Lemon branding and rebranded as Durian Cloud SMS while keeping the same servers intact. This indicated continuity of the operation despite the name change.
Trend Micro published research on the Lemon Group and its preinfected-device cybercriminal ecosystem in February 2022. The reporting identified the operation as using infected Android devices for monetization and abuse.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.