BugDrop is an Android dropper associated with the Hadoken group and linked to delivery of the Xenomorph banking trojan. It masquerades as a benign mobile application, including a QR-code-reader theme, and was identified as an in-development malware component intended to strengthen Android malware distribution. Its behavior centers on obtaining Accessibility Services privileges, contacting command-and-control infrastructure over TOR, retrieving configuration data, and downloading a follow-on payload identified as Xenomorph.
BugDrop appears to reuse and modify code from the Brox, also known as MasterFred, Android malware family. Analysis indicates it was being developed to abuse Android session-based package installation mechanisms in order to bypass Android 13 Restricted Settings protections that hinder sideloaded applications from obtaining sensitive Accessibility permissions. This design goal is significant because it would allow a sideloaded dropper to install a secondary payload in a way that weakens newer Android security controls.
At the time it was observed, BugDrop was not fully functional and contained implementation flaws that prevented successful payload installation. Even so, its architecture and code artifacts indicate a clear role as a malware delivery component for Xenomorph campaigns. BugDrop forms part of the Hadoken group’s evolving distribution chain, which has included multiple Android droppers and binders used to deploy banking malware against financial targets.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Recently, ThreatFabric’s predictions became true, when we discovered an in-development dropper, which we named BugDrop, that criminals have been working on to circumvent this security feature...
Later in the year we saw the Hadoken group switch distribution medium, trying out first BugDrop, and finally landing on Zombinder.
4 distinct techniques documented for this family, organized by ATT&CK tactic.
4 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Android dropper referenced as prior art for session-based installation techniques similar to those used in the analyzed sample.
Distribution mechanism used by the Hadoken group during Xenomorph delivery testing.
An in-development Android dropper posing as a QR code reader. It requests Accessibility Services, contacts an onion.ws C2 over TOR, downloads Xenomorph payloads, and appears designed to abuse session-based installation APIs to bypass Android 13 restricted-setting protections.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.