Dvmap

MITRE ATT&CK: S0420 View on attack.mitre.org

Aliases: Dvmap

First seen
2017-06-01 00:00:00
Malware type
rootkit
Family
Malware family
Operating systems
android
Related IoCs
1 (1 malicious)
Last IoC activity
2026-07-30 01:27:32
Profile updated
2026-07-07 14:03:57

Context

Dvmap is rooting malware that injects malicious code into system runtime libraries. It is credited with being the first malware that performs this type of code injection.

Recent IoC activity

1 malicious indicator in Maltiverse are attributed to Dvmap (S0420). The 1 most recently updated:

TypeIndicatorUpdatedSources
file sample 220603-hsshksggdm.bin 2026-07-30 2

Malware & tools used

  • Download New Code at Runtime (attack-pattern)
  • System Runtime API Hijacking (attack-pattern)
  • System Information Discovery (attack-pattern)
  • Code Signing Policy Modification (attack-pattern)
  • Disable or Modify Tools (attack-pattern)
  • Exploitation for Privilege Escalation (attack-pattern)
  • Obfuscated Files or Information (attack-pattern)

Reports & references

  • Kaspersky — 96280 (report)
  • malpedia.caad.fkie.fraunhofer.de — Apk.Dvmap (report)
  • Kaspersky — 78648 (report)
  • MITRE ATT&CK — S0420 (report)

External references