Dendroid
MITRE ATT&CK: S0301 View on attack.mitre.org
Aliases: Dendroid
- First seen
- 2014-03-01 00:00:00
- Malware type
- rat
- Family
- Malware family
- Operating systems
- android
- Related IoCs
- 8 (8 malicious)
- Last IoC activity
- 2026-07-06 04:00:55
- Profile updated
- 2026-07-07 15:46:02
Context
Dendroid is an Android remote access tool (RAT) primarily targeting Western countries. The RAT was available for purchase for $300 and came bundled with a utility to inject the RAT into legitimate applications.
Recent IoC activity
8 malicious indicators in Maltiverse are attributed to Dendroid (S0301). The 8 most recently updated:
| Type | Indicator | Updated | Sources |
|---|---|---|---|
| file sample | 099a57328de9335c524f44514e225d50731c808145221affdd684d8b4dad5a1d | 2026-07-06 | 2 |
| hostname | somrasdc.ddns.net | 2025-12-06 | 1 |
| hostname | wwwgoogl.zapto.org | 2025-12-06 | 1 |
| hostname | immigrationvisaexpert.com | 2025-10-31 | 1 |
| URL | http://146.185.178.75/dendroid/ | 2025-09-30 | 1 |
| URL | http://aaictlogistics.com/panel/ | 2025-09-30 | 1 |
| URL | http://immigrationvisaexpert.com/backup/mobile/setup/ | 2025-09-30 | 1 |
| URL | http://casperdroid.jux.in | 2025-09-30 | 1 |
Malware & tools used
- System Checks (attack-pattern)
- SMS Messages (attack-pattern)
- GUI Input Capture (attack-pattern)
- Data from Local System (attack-pattern)
- Match Legitimate Name or Location (attack-pattern)
- SMS Control (attack-pattern)
- Audio Capture (attack-pattern)
- Video Capture (attack-pattern)
Reports & references
- cocomelonc.github.io — Aiya Mmd Book (report)
- malpedia.caad.fkie.fraunhofer.de — Apk.Dendroid (report)
- Broadcom/Symantec — Viewdocument (report)
- MITRE ATT&CK — S0301 (report)
- blog.lookout.com — Dendroid (report)
- github.com — Dendroid (report)
- github.com — Dendroid (report)