Researchers reported multiple Google Play Store campaigns distributing the Hydra Android banking trojan through seemingly benign dropper apps. One campaign used a fake "Document Manager" app that drew more than 10,000 downloads and prompted users to install a supposed update, which fetched a second-stage APK from attacker-controlled infrastructure. Earlier analysis of Hydra-linked droppers found similar Play Store distribution between 2018 and 2019, with malware using overlay attacks to steal banking credentials and targeting users in specific regions, including checks for Turkish devices and later activity aligned with campaigns against users in Colombia.
Technical analysis showed Hydra operators separating the downloader from the banking payload to reduce detection. Samples used minimal initial permissions such as REQUEST_INSTALL_PACKAGES, then unpacked additional components through dropped DEX files, including one case where the payload was reconstructed from a PNG asset using steganography-like methods and loaded via the native library libhoter.so. Once installed, Hydra variants were observed stealing SMS messages, cookies, OTPs, and device lock PINs, abusing Accessibility Services to hinder removal, and using command-and-control infrastructure, including TOR-related communications, to manage infections and deliver malicious modules.

Pull IOCs and campaign context straight into your stack.
6 events from the most recent confirmed update back to the earliest known activity.
Cyble reported that the malicious 'Document Manager' downloader app was released on the Google Play Store on June 3, 2022, where it later amassed more than 10,000 downloads.
Cyble reported that the fake 'Document Manager' app used to deliver Hydra was updated on the Google Play Store on May 30, 2022.
Cyble reported that Hydra campaigns in April targeted Colombia through phishing sites, representing activity before the later Play Store distribution shift.
The Pentest Blog analysis links the sample's native time validation to a date around April 6, 2019, corresponding to the period when the malicious app was on the Play Store.
The same analysis says Hydra dropper apps remained on Google Play Store through March 2019, showing sustained Play Store distribution over that period.
The Pentest Blog analysis states that at least 8 to 10 Hydra samples were distributed through dropper apps on the Google Play Store between July 2018 and March 2019.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 18 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.