LSDroid
Profile
Organisation tracking is available to eligible accounts.
Profile narrative
LSDroid is an alias associated with malicious software activity targeting the Android mobile platform. The name reflects a focus on mobile threats, specifically those designed to compromise Android devices and the users who rely on them for communication, personal data storage, and financial transactions. Mobile malware operators such as LSDroid typically distribute their tools through unofficial app stores, malicious links, or trojanised versions of legitimate applications, seeking to harvest credentials, intercept messages, or gain remote control over infected handsets.
The organisation came to public attention following a March 2014 security incident in which it was linked to the compromise of user account data affecting more than 96,000 individuals. According to publicly archived reporting from that period, the breach prompted a password reset action across the affected user base, indicating that LSDroid had obtained access to authentication credentials or related account information at scale. This incident placed LSDroid among the notable mobile malware families of its era, alongside other Android-targeting threats that surfaced as smartphone adoption was rapidly expanding worldwide.
LSDroid functions as a threat actor or malware family designation rather than a conventional commercial enterprise, and its activities sit within the broader ecosystem of cybercrime that exploits mobile platforms. Its operational scope appears to have been oriented toward mass credential harvesting and account takeover, given the volume of users impacted by the documented breach. The alias is used by security researchers and the wider anti-malware industry to track related samples, infrastructure, and tactics associated with this particular lineage of Android malware.
Because LSDroid is documented primarily through its malicious activity rather than through any legitimate corporate filings or public disclosures, there is no available information regarding ownership structure, parent organisations, subsidiaries, or formal corporate governance. The available source material does not indicate any official regulatory standing, recognised industry role, or legitimate service offerings; instead, the documented footprint is limited to the cybersecurity incident recorded in early 2014 and its associated impact on the affected user population.
Incidents
1 incident linked to this organisation.