Triada
MITRE ATT&CK: S0424 View on attack.mitre.org
Aliases: Triada
- First seen
- 2016-01-01 00:00:00
- Malware type
- trojan, downloader
- Family
- Malware family
- Operating systems
- android
- Related IoCs
- 409 (387 malicious)
- Last IoC activity
- 2026-09-02 02:36:56
- Profile updated
- 2026-07-07 14:03:59
Targeted industries: technology-and-telecommunications
Context
Triada was first reported in 2016 as a second stage malware. Later versions in 2019 appeared with new techniques and as an initial downloader of other Trojan apps.
Recent IoC activity
386 malicious indicators in Maltiverse are attributed to Triada (S0424). The 20 most recently updated:
Malware & tools used
- Download New Code at Runtime (attack-pattern)
- SMS Messages (attack-pattern)
- Software Discovery (attack-pattern)
- Compromise Software Supply Chain (attack-pattern)
- Archive Collected Data (attack-pattern)
- Ptrace System Calls (attack-pattern)
- Exfiltration Over C2 Channel (attack-pattern)
- Generate Traffic from Victim (attack-pattern)
Reports & references
- Kaspersky — 96280 (report)
- malpedia.caad.fkie.fraunhofer.de — Apk.Triada (report)
- blog.checkpoint.com — In The Wild Mobile Malware Implements New Features (report)
- Kaspersky — 74032 (report)
- security.googleblog.com — Pha Family Highlights Triada (report)
- Kaspersky — 103679 (report)
- Kaspersky — 74997 (report)
- contagiominidump.blogspot.de — Android Triada Modular Trojan (report)
- arstechnica.com — Google Confirms 2017 Supply Chain Attack That Sneaked Backdoor On Android Devices (report)
- Kaspersky — 101845 (report)
- nowsecure.com — Android Malware Analysis Radare Triada Trojan (report)
- MITRE ATT&CK — S0424 (report)
- kaspersky.com — 11481 (report)