LARVA-398 is a financially motivated cybercriminal threat actor associated with the operation and sale of the AntiDot Android botnet as a malware-as-a-service offering. The group’s activity centers on mobile-device compromise, particularly Android infections that enable remote control of victim devices and theft of sensitive user data. AntiDot is a multi-stage, heavily obfuscated Java-based malware platform that incorporates its own loader, packer, and botnet infrastructure, indicating a mature criminal service model rather than a single-use implant. Operations attributed to LARVA-398 show a focus on credential and payment-data theft from cryptocurrency, financial, and payment-related applications. The malware abuses Android accessibility services to monitor active applications, collect screen content, simulate user interaction, and deploy phishing overlays that mimic legitimate apps. It also supports screen recording, interface cloning, SMS interception, notification suppression, and real-time operator control through a websocket-enabled command-and-control panel. Additional functionality includes attempts to obtain default SMS privileges, read/send/delete SMS messages, and monitor call information through abuse of Android roles and permissions. Campaign patterns indicate selective victim targeting by geography and language, suggesting tailored criminal operations rather than indiscriminate mass infection alone. Distribution has been linked to malicious advertising networks and phishing activity. The AntiDot ecosystem has been observed supporting hundreds of campaigns and thousands of infected devices, reflecting sustained operational scale. No high-confidence evidence in the supplied facts supports attribution to a nation-state; the available evidence instead supports classification as a financially motivated malware-as-a-service operator.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
4 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Financially motivated operator behind AntiDot Android malware, sold as MaaS and used in numerous mobile campaigns.
Operates and sells the AntiDot Android botnet as a MaaS offering, supporting targeted campaigns delivered via malicious advertising networks and suspected phishing, with localized victim targeting by language and geography.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.