TF-MAL-apk.triada
📛 Threat Title
Malware family: Triada
Description
ThreatFox malware family `apk.triada`. Printable name: Triada.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
apk.triada
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.triada
IOC database
- Type
- domain
- Value
apk.triada- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-apk.triada
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.triada
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:attack.mitre.org
Triada was first reported in 2016 as a second stage malware . Later versions in 2019 appeared with new techniques and as an initial downloader of other Trojan apps.
-
web:bazaar.abuse.ch
A malware sample can be associated with only one malware family . The page below gives you an overview on malware samples that MalwareBazaar has identified as Triada .
-
web:cybersecsentinel.com
Threat Group: SalesTracker Group, MoYu Group, Lemon Group, LongTV Threat Type: Android Malware Botnet Exploited Vulnerabilities: Supply chain compromises, malicious third-party apps, uncertified Android devices Malware Used: BB2DOOR (variant of Triada ) Threat Score: 🔥 Critical (9.1/10) Last Threat Observation: June 7, 2025 Overview BADBOX 2.0 is a critical
-
web:cybersecurefox.com
BadBox 2.0 represents an advanced evolution of the notorious Triada malware family , demonstrating unprecedented sophistication in its attack vectors. The malware's most concerning characteristic is its ability to establish persistence through pre-installation on budget Android devices during the manufacturing process.
-
web:grokipedia.com
Triada is a highly sophisticated modular Android malware family , first publicly detailed by Kaspersky Lab in March 2016. It is renowned for its innovative persistence mechanism that modifies the Zygote process —the core Android system process serving as a template for every launched application—allowing the malware to embed its code into ...
-
web:malpedia.caad.fkie.fraunhofer.de
Triada is a remote access trojan (RAT) malware that is used to compromise Android devices in order to steal confidential and sensitive information such as credit card numbers, passwords, bank account information, etc. It also provides a backdoor for attackers to include the device as part of a botnet and perform other malicious activities.
-
web:thehackernews.com
Triada malware infected 2,600+ Android devices via counterfeit phones in March 2025, enabling remote access and crypto theft.
-
web:www.cisa.gov
It highlights technical approaches to uncovering malicious activity and includes mitigation steps according to best practices. The purpose of this report is to enhance incident response among partners and network administrators along with serving as a playbook for incident investigation.
-
web:www.darktrace.com
Explore the intricacies of the Triada Trojan and its targeting of communication and banking apps. Learn how to safeguard against this threat.
-
web:www.pcrisk.com
What kind of malware is Triada ? Triada is the name of a Trojan targeting Android users. Cybercriminals distribute this Trojan via a modified version of WhatsApp called FMWhatsapp (and possibly other apps). Once the app with Triada hidden in it is launched, the Trojan gathers various device information to set up a communication channel and drops additional payloads via a remote server. More ...
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.