logo

Lemon Group’s Cybercriminal Businesses Built on Preinfected Devices

ID: ea344187-c436-5e9c-abb2-b7ba8dec06f3

STIX ID: report--ea344187-c436-5e9c-abb2-b7ba8dec06f3

Feed Name: TrendAI Security Blog

Threat Score
85/100

Date Published: 2026-01-01

Date Updated: 2026-08-21

...
...

This report analyzes a large-scale mobile supply-chain campaign by a criminal group dubbed “Lemon Group” that preinstalls Guerrilla/Sloth malware into device firmware. The implant modifies zygote libraries to load fileless DEX payloads and multiple plugins that intercept SMS (including OTPs), harvest cookies and WhatsApp sessions, set up reverse proxies, perform silent installs and serve ads; the actors monetize compromised devices via SMS PVA services, proxy resale and marketing. Trend Micro telemetry and forensic analysis identified dozens of infected firmware images, global device distribution, rebranding to “Durian Cloud SMS,” and multiple file-hash indicators of compromise.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.