Malicious Triada binder.so Planted in Android System Framework

PremiumReviewedSigma · High · v1
Product
android
Category
file_event
Author
HuntRule
Published
2026-06-23
Updated
2026-08-28

What it detects

This rule detects creation of a binder.so library inside the Android system framework arm directory which the Triada trojan replaces to hook Zygote and inject into every app process. This system-level modification gives the malware persistent control over the device including clipboard wallet clipping and premium SMS abuse. A write to the framework native library path is highly abnormal on a clean device.

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.