Roaming Mantis is a financially motivated cybercrime threat actor and long-running mobile-focused campaign associated with Android malware including MoqHao, Wroba, XLoader, and in related activity FakeCop, FakeSpy, and FunkyBot. The group is assessed as Chinese-speaking and has been publicly tracked since at least 2017–2018. It initially concentrated on Asian targets, especially Japan, South Korea, and Taiwan, and later expanded into Europe, the Middle East, Africa, Oceania, and the Americas. Roaming Mantis is best known for large-scale smishing operations that deliver links to malicious landing pages. Those pages commonly perform geofencing and device fingerprinting to tailor follow-on content: Android users are prompted to install trojanized APKs, while iPhone users are redirected to credential-harvesting pages impersonating Apple services. The actor has also used phishing sites themed around postal, delivery, and package notifications, as well as browser or application update lures. In earlier phases, the campaign also relied on DNS hijacking through compromised routers to redirect victims to malicious infrastructure. Its Android tooling functions as a remote access trojan, spyware, and banking malware, enabling theft of device information, messages, contacts, application data, and credentials. Reported capabilities include command-and-control retrieval through dead-drop resolvers on legitimate platforms, extensive permission abuse on Android devices, and backdoor functionality for remote tasking. Roaming Mantis has also used router-focused DNS changer functionality that checks router models, abuses weak or default administrative credentials, and alters DNS settings to redirect traffic. Operational refinements have included dynamic generation of APK payloads, randomized delivery artifacts, multilingual landing pages, and selective responses intended to reduce researcher visibility. The actor has targeted both Android and iOS users for monetization. Android infections support fraud and information theft, while iOS activity has centered on credential phishing. Additional monetization schemes reported in Roaming Mantis operations include banking fraud and cryptocurrency-related abuse. Overall, Roaming Mantis is a globally active mobile-centric cybercrime actor distinguished by smishing-led initial access, credential theft, malware delivery, DNS hijacking, and broad international targeting.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
Attributed origin per open-source reporting.
32 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
10 malware families attributed to this actor across reporting.
5 additional families tracked in Mallory.
256 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducting a large-scale smishing campaign targeting mobile users in France, delivering MoqHao to Android devices and harvesting Apple credentials from iPhone users.
Roaming Mantis is known for distributing the MoqHao Android malware family, primarily via SMS-based phishing (smishing) campaigns. The group targets users in Asian countries and has recently expanded to other regions. Their latest MoqHao variants can auto-execute upon installation, use Unicode tricks to disguise as legitimate apps, leverage social engineering to become the default SMS app, and use legitimate services like Pinterest to update phishing content. The malware is capable of stealing SMS, contacts, device info, photos, and more, and can send phishing messages to further propagate itself.
Roaming Mantis is associated with MoqHao/Wroba campaigns targeting mobile users globally, using SMS phishing (smishing) to distribute spyware and banking malware, with earlier focus on Japan, Taiwan, and the US and more recent targeting of European countries.
Financially motivated smishing campaigns delivering MoqHao to Android users, with operations expanding from East Asia to global targeting across Africa, Asia, Europe, North America, Oceania, and parts of South America.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.