Researchers reported a large Android supply-chain compromise in which devices from more than 50 brands were shipped with malware embedded in firmware, allowing attackers to control phones before users installed any apps. Trend Micro said the operation, attributed to Lemon Group, implanted Guerrilla malware through a tampered zygote-related library and used a core plugin called Sloth to fetch modules for SMS interception, proxying, cookie theft, WhatsApp abuse, ad fraud, and silent app installation. Telemetry and actor-hosted data indicated activity across more than 180 countries, hundreds of thousands of mobile numbers used for OTP requests, and millions of potentially affected devices, with the business later rebranded in part from Lemon SMS to Durian Cloud SMS while keeping backend infrastructure.
The findings echo earlier reporting on Triada, an Android malware family that evolved from a rooting trojan into a preinstalled system-image backdoor embedded in framework components. Google previously said Triada abused privileged contexts such as System UI and Google Play to execute code, monitor foreground apps, replace ads, and install applications so they appeared to come from Google Play, and that infections were inserted into device images during production by a third party using the names Yehuo or Blazefire. Trend Micro said the newer Guerrilla campaign showed infrastructure overlap with Triada operators, suggesting a continuing ecosystem of firmware-level Android compromise monetized through fraud, silent installs, and persistent device backdoors.

Trace attribution and downstream blast radius.
9 events from the most recent confirmed update back to the earliest known activity.
Trend Micro published research on Lemon Group's preinfected-device operation, including forensic analysis of a tampered ROM, Guerrilla malware plugins, and telemetry showing large-scale abuse of infected phones. The report also says researchers observed infrastructure overlap with Triada operators and assessed the two likely worked together at some point.
Trend Micro says that after publication of earlier research in February 2022, the group changed its operation name. This publication preceded a later rebrand of parts of the service while backend servers remained the same.
Google published an analysis of the Triada malware family, describing its evolution, monetization methods, and assessment that infections were introduced into device system images during production by a third party believed to use the name Yehuo or Blazefire. Google also said it coordinated with OEMs on OTA updates and used Google Play Protect and system image scanning to detect and remove Triada.
Trend Micro assesses that the Lemon Group mobile supply-chain criminal network had been established since at least 2018. The operation involved preinfected Android devices carrying Guerrilla malware and monetization plugins.
Google states that Dr.Web first described the backdoored Triada variant that abused the Android framework log function in July 2017. This publicly documented the system-image version of Triada.
In the summer of 2017, Google observed Triada change from a rooting trojan into a preinstalled Android framework backdoor embedded in system images during production. The new variant added malicious code to framework components so it could execute from privileged contexts.
Google's retrospective notes that Kaspersky Lab published a follow-up analysis of Triada in June 2016. This reflected continued public documentation of the malware's early rooting-trojan phase.
Google's analysis says the Triada Android malware family was first discovered in early 2016, and that Kaspersky Lab first described it in March 2016. At that stage, Triada operated as a rooting trojan used to install spam apps and monetize ad fraud.
Trend Micro reports that in May, after the February 2022 research, the group rebranded parts of its service from Lemon SMS to Durian Cloud SMS. The report says the servers remained the same after the rebrand.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 11 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
3 references tracked. Mallory keeps watching after this page renders.
trendaisecurity.com
Open sourcesecurity.googleblog.com
Open sourcekaspersky.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.