Check Point Research reported that the Rogue mobile remote-access trojan resurfaced through a dark-web operation tied to the actors Triangulum and HeXaGoN Dev, who developed, marketed, and sold Android malware. Investigators said Rogue was not a wholly new family but an evolution of earlier projects, blending elements from HeXaGoN’s DarkShades/Cosmos RAT lineage with leaked Hawkshaw code, while continuing to be promoted and sold even after the Rogue package itself was leaked.
The malware was built for broad surveillance and device control on Android, abusing permissions and accessibility features to maintain persistence and harvest victim data. Researchers said Rogue also relied on Google Firebase services for command-and-control and data exfiltration, highlighting how legitimate cloud infrastructure was used to support the campaign’s operations and conceal malicious activity behind a commercial mobile malware business model.

Pull IOCs and campaign context straight into your stack.
11 events from the most recent confirmed update back to the earliest known activity.
In January 2021, Check Point Research published its investigation into Triangulum, HeXaGoN Dev, and the Rogue Android MRAT, describing Rogue as a combination of DarkShades/Cosmos and leaked Hawkshaw code.
Check Point Research noted that the Rogue Android malware package had been leaked by April 2020, though sales activity continued afterward.
In April 2020, Triangulum attempted to sell malware on a Russian darknet forum but failed to gain trust because he would not provide a demo video.
Three days after DarkShades was first offered for sale in August 2019, the project was sold to Triangulum, who then opened a new sales thread for it.
In August 2019, HeXaGoN Dev began selling the DarkShades Android malware project, a code base later linked to Rogue.
On April 6, 2019, Triangulum resurfaced after about a year and a half of inactivity and offered another malware product for sale.
On October 20, 2017, Triangulum posted his first malware offering for sale on darknet forums.
On June 10, 2017, Triangulum demonstrated an Android mobile RAT that could exfiltrate sensitive data to a command-and-control server and destroy local data, including the operating system.
The Hawkshaw Android malware source code was leaked in 2017 and remained publicly available online, later becoming one of the code bases incorporated into Rogue.
Check Point Research reported that the actor Triangulum appears to have started operating on darknet forums in early 2017, laying the groundwork for later Android malware sales.
Within roughly half a year of his April 2019 return, Triangulum had advertised four different malware products on darknet forums, showing a rapid expansion of his offerings.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 57 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.