Wibag is an Android spyware family identified in Iraq. It masquerades as a legitimate mobile application and is designed to surveil victims’ communications and device activity. Reported collection includes SMS messages, call logs, location data, contacts, screen recordings, and call recordings, indicating a broad mobile surveillance capability focused on intelligence gathering from handheld devices. Wibag targets users of major messaging and social media platforms, including Telegram, WhatsApp, Instagram, Facebook, and Snapchat. Its use of application masquerading supports initial access through social engineering, after which it performs data collection and exfiltration from compromised Android devices. The spyware’s branding and operational context suggest a likely Iraq-linked surveillance use case, but publicly available information does not support a more specific attribution to a named state or organization at high confidence. Wibag is best characterized as a mobile spyware operation oriented toward covert monitoring and information theft rather than ransomware or disruptive activity.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
Attributed origin per open-source reporting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.