Kaspersky reported that a Triada Android malware module was hijacking mobile web traffic through browser URL spoofing after gaining superuser privileges on infected devices. Detected as Backdoor.AndroidOS.Triada.p, Backdoor.AndroidOS.Triada.o, and Backdoor.AndroidOS.Triada.q, the module injected a DLL into browser processes and then downloaded URL-rewrite rules from its command-and-control infrastructure to silently alter where victims were sent online.
The activity was observed redirecting users by changing default search engines and browser home pages, but the same mechanism could also be used to send victims visiting banking sites to phishing pages controlled by attackers. Kaspersky said the campaign affected 247 users during the observation period and found no indication that the operation was slowing, underscoring the risk of persistent mobile malware capable of covert traffic manipulation.

Pull IOCs and campaign context straight into your stack.
2 events from the most recent confirmed update back to the earliest known activity.
Kaspersky Lab detected the modular Android Trojan Backdoor.AndroidOS.Triada in early March 2016. The malware granted superuser privileges to downloaded payloads and could embed itself into Android system processes.
On March 15, Kaspersky found a Triada module that enabled browser URL spoofing attacks by injecting a DLL into targeted browser processes after gaining superuser privileges. The module downloaded URL-rewrite rules from its command-and-control server and could silently redirect users to attacker-chosen pages.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.