Researchers detailed Triada, a modular Android Trojan that gains unauthorized root privileges through an ecosystem of rooting malware and ad-fraud botnets, then embeds itself in system application directories to survive reboots and evade removal. The malware downloads additional modules directly into memory, collects device identifiers and installed-app data, and communicates with hard-coded command-and-control servers while storing encrypted configuration data locally.
Triada’s most notable capability is patching Android’s Zygote process so its code is injected into nearly every app launched on an infected device, giving it broad visibility and control across the system. Operators used that access to monetize infections through SMS fraud, intercepting and altering outgoing messages tied to in-app payments so charges were redirected to attacker-controlled numbers, while filtering incoming SMS and hiding malicious packages, processes, and services from users and security tools.

Pull IOCs and campaign context straight into your stack.
3 events from the most recent confirmed update back to the earliest known activity.
Kaspersky's Securelist article described Triada as a modular Android Trojan that gained superuser privileges, installed itself in system directories, loaded modules only in memory, and patched the Android Zygote process to inject code into nearly all launched apps. The report also detailed its SMS-fraud monetization, interception of outgoing and incoming SMS, and stealth hooks that hid its components from users and security tools.
The Securelist report states that Trojans with superuser privileges attacked about 10% of Android-based mobile devices in the second half of 2015. This rooting-malware ecosystem later served as a distribution channel for Triada.
Triada was distributed through an Android advertising botnet formed by rooting malware families including Leech, Ztorg, Gorpo, and Trojan.AndroidOS.Iop. These threats used unauthorized root access to install apps, show aggressive advertising, and deliver additional malware such as Triada.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 14 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.