
Back in 2016, a malware called Triadawas first discovered by Kaspersky Lab. According to the security experts who studied it, it is a rooting Trojanthat exploits a machine by gaining access to sensitive parts of its operating system.
Once the Trojan is installed, it starts installing spam applications on the device, which it downloads from a command and control server. These applications in turn display advertisements on the affected devices, and when the user clicks on one of them, the hackers earn money.
But Triada doesn't just install apps. It also injects code into four different browsers, which can replace the ads displayed on websites with ones that generate money for the malicious actor. Some of the browsers that can be affected by Triada include AOSP, 360 Secure, Cheetah, and Oupeng.
To ensure that a device has enough space to install spam apps, Triada exploits a feature called weight watching, which rates an app or file based on its installation date and certificate. Apps that are not pre-installed on a device are usually the first to be removed by the malware to make room for the apps it wants to install.
To address this, Google has introduced improvements to Google Play Protect, which allow the software to automatically detect the Trojan. Additionally, improvements made to the Android operating system have limited the malware's impact on devices running older versions of Google's operating system.
But the malicious actors weren't willing to give up so easily, so they found a way to continue distributing Triada to devices before they were available for sale.
To achieve this, they exploit the process in which third-party vendors introduce additional functionality into the device's system, ensuring that Triada is among the vendors' files.
To respond to newer software versions, Triada injects code into the Google Play app. This way, the malware can install spam apps without appearing to come from the Play Store and without having to change the device settings and enable the “Install from unknown sources” option.
To resolve this issue, Google had to deploy updates that remove files associated with the Triada malware, while to prevent future cases of malware distribution, the company is also offering its Test Build suite to mobile phone manufacturers.
