Lemon Groupâs Cybercriminal Businesses Built on Preinfected Devices
ID: ea344187-c436-5e9c-abb2-b7ba8dec06f3
STIX ID: report--ea344187-c436-5e9c-abb2-b7ba8dec06f3
Feed Name: TrendAI Security Blog
This report analyzes a large-scale mobile supply-chain campaign by a criminal group dubbed “Lemon Group” that preinstalls Guerrilla/Sloth malware into device firmware. The implant modifies zygote libraries to load fileless DEX payloads and multiple plugins that intercept SMS (including OTPs), harvest cookies and WhatsApp sessions, set up reverse proxies, perform silent installs and serve ads; the actors monetize compromised devices via SMS PVA services, proxy resale and marketing. Trend Micro telemetry and forensic analysis identified dozens of infected firmware images, global device distribution, rebranding to “Durian Cloud SMS,” and multiple file-hash indicators of compromise.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
