Researchers reported multiple Google Play Store campaigns distributing the Hydra Android banking trojan through seemingly benign dropper apps. One campaign used a fake "Document Manager" app that drew more than 10,000 downloads and prompted users to install a supposed update, which fetched a second-stage APK from attacker-controlled infrastructure. Earlier analysis of Hydra-linked droppers found similar Play Store distribution between 2018 and 2019, with malware using overlay attacks to steal banking credentials and targeting users in specific regions, including checks for Turkish devices and later activity aligned with campaigns against users in Colombia.
Technical analysis showed Hydra operators separating the downloader from the banking payload to reduce detection. Samples used minimal initial permissions such as REQUEST_INSTALL_PACKAGES, then unpacked additional components through dropped DEX files, including one case where the payload was reconstructed from a PNG asset using steganography-like methods and loaded via the native library libhoter.so. Once installed, Hydra variants were observed stealing SMS messages, cookies, OTPs, and device lock PINs, abusing Accessibility Services to hinder removal, and using command-and-control infrastructure, including TOR-related communications, to manage infections and deliver malicious modules.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
Cyble reported that the malicious 'Document Manager' downloader app was released on the Google Play Store on June 3, 2022, where it later amassed more than 10,000 downloads.
Cyble reported that the fake 'Document Manager' app used to deliver Hydra was updated on the Google Play Store on May 30, 2022.
Cyble reported that Hydra campaigns in April targeted Colombia through phishing sites, representing activity before the later Play Store distribution shift.
The Pentest Blog analysis links the sample's native time validation to a date around April 6, 2019, corresponding to the period when the malicious app was on the Play Store.
The same analysis says Hydra dropper apps remained on Google Play Store through March 2019, showing sustained Play Store distribution over that period.
The Pentest Blog analysis states that at least 8 to 10 Hydra samples were distributed through dropper apps on the Google Play Store between July 2018 and March 2019.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.