logo

Triada strikes back

ID: f1e91f56-3020-56b5-98ba-0681aa0bbf0e

STIX ID: report--f1e91f56-3020-56b5-98ba-0681aa0bbf0e

Feed Name: Securelist by Kaspersky

Threat Score
85/100

Date Published: 2025-04-25

Date Updated: 2026-04-29

Author: Dmitry Kalinin

...
...

Executive summary: Kaspersky researchers describe an evolved Triada Trojan persistently embedded in Android device firmware (pre-sale counterfeit/compromised devices) that infects the Zygote process and injects modular payloads into every app. Modules enable cryptocurrency address replacement/clipboard hijacking, credential and cookie theft from messaging/social apps and browsers, SMS interception and premium-SMS abuse, link substitution in browsers, reverse-proxying of network traffic, and remote payload delivery; the report includes technical analysis, IOCs (hashes, domains, IPs, GitHub configs), and telemetry showing thousands of detections.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.