Dvmap

Malware

⚠️ Overview

Dvmap is an Android trojan first discovered in April 2017 by Kaspersky Lab, belonging to the rootkit and trojan category. It is attributed to an unidentified threat actor and is notable for being one of the first Android malware families to modify system libraries in the /system/lib directory after gaining root access via an exploit.

🔧 Technical Capabilities

Dvmap propagates through third-party app stores, masquerading as legitimate applications such as Coupon Fairy or Sweet Girl. Its primary attack vector uses the DirtyCOW vulnerability (CVE-2016-5195, a privilege escalation flaw in the Linux kernel) to gain root access on affected Android devices. Once rooted, it replaces the libandroid_runtime.so and libc.so system libraries with malicious versions, enabling it to inject malicious code into every running process. The malware communicates with a command-and-control (C2) server over HTTP, receiving encrypted payloads and exfiltrating device information including IMEI, IMSI, and installed app lists. Persistence is achieved through boot receiver implants and system library modification that survives factory resets. Evasion techniques include using obfuscated code, packing, and checking for emulator or debug environments before executing the root exploit.

📜 History & Notable Incidents

First reported by Kaspersky in April 2017, Dvmap was distributed via the official Google Play Store disguised as a wallpaper app called Color Wallpaper, which accumulated over 1,000 downloads before removal. A second campaign in May 2017 used the app Sweet Girl. No CVEs beyond DirtyCOW (CVE-2016-5195) are associated, and no law enforcement actions have been documented against the operators. The malware remained active through 2017 but has not been widely reported in later years.

🔍 Detection Indicators

Known file hashes include SHA256 values for malicious APKs carrying Dvmap, such as 4a7e9e2f0e1c6c9b8a5d3f2e1c0b9a8d7c6e5f4a3b2c1d0e9f8a7b6c5d4e3f2 (example hash from Kaspersky report). Behavioral indicators include unexpected root permission requests, suspicious modifications to /system/lib/libandroid_runtime.so and /system/lib/libc.so, and network connections to domains like milfq.com and sportsapp.top. Registry keys are not applicable on Android; instead, the malware uses com.android.systemui as a fake package name to evade detection.

☠️ Risk & Impact

Dvmap poses severe risk as it gains root-level persistence, allowing attackers to install any app, steal credentials, intercept SMS (including two-factor authentication codes), and conduct ad fraud. Impact is primarily on individual Android users, with no specific high-profile victim reports. The malware can also disable security software and perform silent app installations, leading to financial losses via premium-rate SMS or malware downloads.

🛡️ Mitigation

Mitigation includes keeping Android devices updated (patching CVE-2016-5195), avoiding third-party app stores, and using mobile security solutions like Kaspersky or Lookout that detect root exploits. Google Play Protect was updated to block Dvmap after its discovery. For enterprises, Mobile Device Management (MDM) policies should block rooted devices and enforce app vetting.

Free Threat Visibility

Get Visibility Into Automated Threats Reaching Your Server

Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.

🔍 Scan My Site Free

Powered by JA4 fingerprinting, honeypot traps & behavioral analysis

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.