Suspicious Triada mms-core.jar Backdoor Dropped in App Data

PremiumReviewedSigma · High · v1
Product
android
Category
file_event
Author
HuntRule
Published
2026-06-30
Updated
2026-08-28

What it detects

This rule detects creation of an mms-core.jar file within an application data directory which the Triada trojan drops as a backdoor module loaded into hooked processes. This module implements the trojan command handling used to intercept SMS and manipulate clipboard cryptocurrency addresses. The specific filename in a per-app data path is a reliable Triada artifact.

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.