Dendroid

MITRE ATT&CK: S0301 View on attack.mitre.org

Aliases: Dendroid

First seen
2014-03-01 00:00:00
Malware type
rat
Family
Malware family
Operating systems
android
Related IoCs
8 (8 malicious)
Last IoC activity
2026-07-06 04:00:55
Profile updated
2026-07-07 15:46:02

Context

Dendroid is an Android remote access tool (RAT) primarily targeting Western countries. The RAT was available for purchase for $300 and came bundled with a utility to inject the RAT into legitimate applications.

Recent IoC activity

8 malicious indicators in Maltiverse are attributed to Dendroid (S0301). The 8 most recently updated:

TypeIndicatorUpdatedSources
file sample 099a57328de9335c524f44514e225d50731c808145221affdd684d8b4dad5a1d 2026-07-06 2
hostname somrasdc.ddns.net 2025-12-06 1
hostname wwwgoogl.zapto.org 2025-12-06 1
hostname immigrationvisaexpert.com 2025-10-31 1
URL http://146.185.178.75/dendroid/ 2025-09-30 1
URL http://aaictlogistics.com/panel/ 2025-09-30 1
URL http://immigrationvisaexpert.com/backup/mobile/setup/ 2025-09-30 1
URL http://casperdroid.jux.in 2025-09-30 1

Malware & tools used

  • System Checks (attack-pattern)
  • SMS Messages (attack-pattern)
  • GUI Input Capture (attack-pattern)
  • Data from Local System (attack-pattern)
  • Match Legitimate Name or Location (attack-pattern)
  • SMS Control (attack-pattern)
  • Audio Capture (attack-pattern)
  • Video Capture (attack-pattern)

Reports & references

  • cocomelonc.github.io — Aiya Mmd Book (report)
  • malpedia.caad.fkie.fraunhofer.de — Apk.Dendroid (report)
  • Broadcom/Symantec — Viewdocument (report)
  • MITRE ATT&CK — S0301 (report)
  • blog.lookout.com — Dendroid (report)
  • github.com — Dendroid (report)
  • github.com — Dendroid (report)

External references