Triada

MITRE ATT&CK: S0424 View on attack.mitre.org

Aliases: Triada

First seen
2016-01-01 00:00:00
Malware type
trojan, downloader
Family
Malware family
Operating systems
android
Related IoCs
409 (387 malicious)
Last IoC activity
2026-09-02 02:36:56
Profile updated
2026-07-07 14:03:59

Targeted industries: technology-and-telecommunications

Context

Triada was first reported in 2016 as a second stage malware. Later versions in 2019 appeared with new techniques and as an initial downloader of other Trojan apps.

Recent IoC activity

386 malicious indicators in Maltiverse are attributed to Triada (S0424). The 20 most recently updated:

Malware & tools used

  • Download New Code at Runtime (attack-pattern)
  • SMS Messages (attack-pattern)
  • Software Discovery (attack-pattern)
  • Compromise Software Supply Chain (attack-pattern)
  • Archive Collected Data (attack-pattern)
  • Ptrace System Calls (attack-pattern)
  • Exfiltration Over C2 Channel (attack-pattern)
  • Generate Traffic from Victim (attack-pattern)

Reports & references

  • Kaspersky — 96280 (report)
  • malpedia.caad.fkie.fraunhofer.de — Apk.Triada (report)
  • blog.checkpoint.com — In The Wild Mobile Malware Implements New Features (report)
  • Kaspersky — 74032 (report)
  • security.googleblog.com — Pha Family Highlights Triada (report)
  • Kaspersky — 103679 (report)
  • Kaspersky — 74997 (report)
  • contagiominidump.blogspot.de — Android Triada Modular Trojan (report)
  • arstechnica.com — Google Confirms 2017 Supply Chain Attack That Sneaked Backdoor On Android Devices (report)
  • Kaspersky — 101845 (report)
  • nowsecure.com — Android Malware Analysis Radare Triada Trojan (report)
  • MITRE ATT&CK — S0424 (report)
  • kaspersky.com — 11481 (report)

External references