Dvmap
MITRE ATT&CK: S0420 View on attack.mitre.org
Aliases: Dvmap
- First seen
- 2017-06-01 00:00:00
- Malware type
- rootkit
- Family
- Malware family
- Operating systems
- android
- Related IoCs
- 1 (1 malicious)
- Last IoC activity
- 2026-07-30 01:27:32
- Profile updated
- 2026-07-07 14:03:57
Context
Dvmap is rooting malware that injects malicious code into system runtime libraries. It is credited with being the first malware that performs this type of code injection.
Recent IoC activity
1 malicious indicator in Maltiverse are attributed to Dvmap (S0420). The 1 most recently updated:
| Type | Indicator | Updated | Sources |
|---|---|---|---|
| file sample | 220603-hsshksggdm.bin | 2026-07-30 | 2 |
Malware & tools used
- Download New Code at Runtime (attack-pattern)
- System Runtime API Hijacking (attack-pattern)
- System Information Discovery (attack-pattern)
- Code Signing Policy Modification (attack-pattern)
- Disable or Modify Tools (attack-pattern)
- Exploitation for Privilege Escalation (attack-pattern)
- Obfuscated Files or Information (attack-pattern)
Reports & references
- Kaspersky — 96280 (report)
- malpedia.caad.fkie.fraunhofer.de — Apk.Dvmap (report)
- Kaspersky — 78648 (report)
- MITRE ATT&CK — S0420 (report)