Skygofree is an advanced Android surveillance implant and backdoor associated with targeted mobile espionage activity. It is designed to provide remote operators with covert control over infected devices using multiple command-and-control channels, including standard web protocols and mobile messaging infrastructure such as HTTP, XMPP, Firebase Cloud Messaging, and older Google Cloud Messaging implementations. This use of common application-layer protocols helps its communications blend with ordinary mobile traffic.
The malware supports intrusive collection functions centered on device surveillance. Documented capabilities include recording audio through the microphone when the device is in a specified location, as well as capturing photos or recording video under location-based conditions. These geofenced collection features indicate an emphasis on contextual espionage against selected victims rather than indiscriminate monetization.
Skygofree targets Android devices. It has been characterized as a sophisticated mobile backdoor, and reporting has noted indications that it may have been developed or marketed in a manner similar to commercial surveillance tooling. An early iOS variant has been mentioned in reporting, but the high-confidence functionality described here is centered on the Android implant. Overall, Skygofree is best understood as a mobile spyware/backdoor platform built for persistent remote surveillance and operator-directed collection on compromised Android devices.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct techniques documented for this family, organized by ATT&CK tactic.
DEFENSOR ID has used Firebase Cloud Messaging for C2; Rotexy can also communicate by using JSON messages sent through Google Cloud Messaging; Skygofree can be controlled via HTTP, XMPP, FirebaseCloudMessaging, or GoogleCloudMessaging in older versions.
AbstractEmu can use HTTP to communicate with the C2 server; AhRat can communicate with the C2 using HTTPS requests; BRATA can use both HTTP and WebSockets to communicate with the C2 server; LightSpy has used both HTTPS and Websockets to communicate with the C2.
Skygofree can be controlled via HTTP, XMPP, FirebaseCloudMessaging, or GoogleCloudMessaging in older versions.
DEFENSOR ID has used Firebase Cloud Messaging for C2. Rotexy can also communicate by using JSON messages sent through Google Cloud Messaging. Skygofree can be controlled via HTTP, XMPP, FirebaseCloudMessaging, or GoogleCloudMessaging in older versions. SpyC23 can communicate with the Command and Control server using HTTPS and Firebase Cloud Messaging (FCM). Trojan-SMS.AndroidOS.Agent.ao uses Google Cloud Messaging (GCM) for command and control. Trojan-SMS.AndroidOS.FakeInst.a uses Google Cloud Messaging (GCM) for command and control. Trojan-SMS.AndroidOS.OpFake.a uses Google Cloud Messaging (GCM) for command and control.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Android spyware that can record video or capture photos, including based on device location.
Mobile spyware/implant controllable over multiple standard protocols including HTTP, XMPP, and cloud messaging services.
Android spyware that can conditionally record microphone audio based on device location.
Skygofree is an advanced mobile backdoor for Android (and an early iOS version), capable of extensive surveillance and control of infected devices, likely sold as a commercial surveillance tool.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.