GymDrop is an Android malware dropper family used to distribute mobile banking trojans through trojanized applications, including apps published on Google Play. It emerged in 2021 and has been associated with the threat actor commonly tracked as the Hadoken group, which has also been linked to Xenomorph operations. GymDrop has been used as delivery infrastructure for multiple Android banking malware families, including Xenomorph, ExobotCompact.D, and Alien, and has also been described in the context of dropper-as-a-service activity supported by a management panel for administering both the dropper and delivered payloads.
GymDrop typically masquerades as benign utility software such as cleaners or similar consumer applications in order to obtain installation at scale. Once installed, it retrieves and deploys secondary payloads onto victim devices. Reported campaigns show that it was capable of reaching large numbers of users through official app-store distribution before removal. Its role is primarily as a staging mechanism rather than as the final banking trojan itself.
The malware targets Android devices and is notable for enabling downstream fraud operations by delivering credential-stealing banking trojans. It has figured prominently in the broader trend of Android banking malware operators using dedicated droppers to separate initial distribution from payload functionality, improving operational flexibility and allowing actors to swap delivered malware families over time.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
the 'Hadoken Security' group claims the ownership of multiple malware families, including the Android Banking trojan Xenomorph and the Dropper Gymdrop...
Xenomorph campaigns have always been characterized by short and contained distribution efforts, first via GymDrop, a dropper operation created and managed by the same group.
4 distinct techniques documented for this family, organized by ATT&CK tactic.
6 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Dropper operation used to distribute early Xenomorph variants.
Android dropper family previously associated with Xenomorph and the actor behind it. It is described as a distribution mechanism used by multiple malware families and compared against BugDrop's evolving installation approach.
Android dropper offered as dropper-as-a-service with an admin/management panel used to manage both the dropper and delivered payloads.
Android dropper trojan distributed via Google Play that delivered ExobotCompact.D/Octo in malicious app campaigns.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.