The Loki Android Trojan was first seen in February 2016 and considered one of the first instance where malware could infect devices and settle inside the core Android operating system processes.  Loki used this as an anti-detection technique to go undetected longer and carry out operations with root privileges. 

Android MalwareNJCCICLoki