Bouncing Golf is an Android-focused threat actor or campaign associated with the delivery of the GolfSpy malware. It has been documented distributing malicious mobile software as repackaged legitimate applications, embedding malicious code within the application package to make the software appear benign to users. The actor has also used hosted application binaries promoted through social media to induce victims to sideload malicious apps, aligning with ATT&CK Mobile initial-access behavior for delivering malicious applications outside authorized app stores. Activity attributed to Bouncing Golf is tied to the mobile domain rather than enterprise intrusion operations. High-confidence reporting supports the use of trojanized or repackaged apps as a primary delivery and defense-evasion mechanism, but does not establish broader attribution, geographic origin, or a wider set of operational objectives with confidence.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
2 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 indicator attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Distributed malware via repackaged legitimate Android applications.
Referenced in MITRE ATT&CK changelog as a named threat group whose software relationship (to GolfSpy) was moved to the Mobile ATT&CK domain; no operational details provided.
Mobile cyber-espionage activity delivering GolfSpy through hosted app binaries promoted on social media.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.