s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-apk.triada

📛 Threat Title

Malware family: Triada

Category: Triada First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `apk.triada`. Printable name: Triada.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain apk.triada VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.triada

IOC database

Type
domain
Value
apk.triada
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-apk.triada

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.triada

References (1)

Remediations (10)

  • web:attack.mitre.org

    Triada was first reported in 2016 as a second stage malware . Later versions in 2019 appeared with new techniques and as an initial downloader of other Trojan apps.

  • web:bazaar.abuse.ch

    A malware sample can be associated with only one malware family . The page below gives you an overview on malware samples that MalwareBazaar has identified as Triada .

  • web:cybersecsentinel.com

    Threat Group: SalesTracker Group, MoYu Group, Lemon Group, LongTV Threat Type: Android Malware Botnet Exploited Vulnerabilities: Supply chain compromises, malicious third-party apps, uncertified Android devices Malware Used: BB2DOOR (variant of Triada ) Threat Score: 🔥 Critical (9.1/10) Last Threat Observation: June 7, 2025 Overview BADBOX 2.0 is a critical

  • web:cybersecurefox.com

    BadBox 2.0 represents an advanced evolution of the notorious Triada malware family , demonstrating unprecedented sophistication in its attack vectors. The malware's most concerning characteristic is its ability to establish persistence through pre-installation on budget Android devices during the manufacturing process.

  • web:grokipedia.com

    Triada is a highly sophisticated modular Android malware family , first publicly detailed by Kaspersky Lab in March 2016. It is renowned for its innovative persistence mechanism that modifies the Zygote process —the core Android system process serving as a template for every launched application—allowing the malware to embed its code into ...

  • web:malpedia.caad.fkie.fraunhofer.de

    Triada is a remote access trojan (RAT) malware that is used to compromise Android devices in order to steal confidential and sensitive information such as credit card numbers, passwords, bank account information, etc. It also provides a backdoor for attackers to include the device as part of a botnet and perform other malicious activities.

  • web:thehackernews.com

    Triada malware infected 2,600+ Android devices via counterfeit phones in March 2025, enabling remote access and crypto theft.

  • web:www.cisa.gov

    It highlights technical approaches to uncovering malicious activity and includes mitigation steps according to best practices. The purpose of this report is to enhance incident response among partners and network administrators along with serving as a playbook for incident investigation.

  • web:www.darktrace.com

    Explore the intricacies of the Triada Trojan and its targeting of communication and banking apps. Learn how to safeguard against this threat.

  • web:www.pcrisk.com

    What kind of malware is Triada ? Triada is the name of a Trojan targeting Android users. Cybercriminals distribute this Trojan via a modified version of WhatsApp called FMWhatsapp (and possibly other apps). Once the app with Triada hidden in it is launched, the Trojan gathers various device information to set up a communication channel and drops additional payloads via a remote server. More ...

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.