PhantomLance is an Android spyware campaign and malware family associated with long-running targeted surveillance activity in South and Southeast Asia. It has been active since at least 2016, with related infrastructure dating to late 2015, and has been attributed with medium confidence to OceanLotus. The operation relied on malicious Android applications distributed through Google Play and third-party app marketplaces, including a tactic in which initially benign applications were later updated to include malicious functionality. Lure applications were tailored to regional users, including Vietnamese-themed apps, and observed targeting included victims in Vietnam, India, Bangladesh, Indonesia, Nepal, Myanmar, and Malaysia.
PhantomLance’s core purpose is covert collection of sensitive information from infected Android devices. Reported capabilities include harvesting geolocation data, call logs, contacts, SMS messages, installed application lists, and general device information. The malware also supports downloading and executing additional payloads, allowing operators to adapt functionality to the victim environment and extend post-compromise access.
Multiple PhantomLance versions have been documented, showing progressive increases in sophistication. Early variants dynamically requested suspicious permissions and concealed parts of their logic to reduce scrutiny. Some variants could abuse undocumented Android functionality via reflection to obtain permissions when root privileges were available. Later versions stored encrypted payloads within application assets, used staged decryption and loading workflows, and incorporated Firebase Remote Config to retrieve material needed to unlock embedded payloads. More advanced variants introduced multi-stage delivery, including additional APK payloads and native components used to maintain persistence. Persistence mechanisms observed across versions included daemon-style native components and earlier use of MarsDaemon-derived techniques.
Operational tradecraft emphasized defense evasion and marketplace abuse. PhantomLance operators used fake developer personas to support app submissions and employed package naming and signing patterns intended to blend with legitimate Android software. The campaign also used staged payload delivery and remote configuration to limit exposure of malicious code during review and to complicate static analysis.
PhantomLance has notable overlaps with previously reported OceanLotus activity across Android, Windows, and macOS, including similarities in infrastructure patterns, code structure, and tradecraft. These cross-platform links place PhantomLance within a broader espionage ecosystem focused on mobile surveillance and long-term access to targeted users and organizations in the Asia-Pacific region.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
we conducted an inquiry of our own, discovering a long-term campaign, which we dubbed “PhantomLance”... Functionality of all samples are similar – the main purpose of spyware was to gather sensitive information.
14 distinct techniques documented for this family, organized by ATT&CK tactic.
No suspicious permissions are mentioned in the manifest file; instead, they are requested dynamically and hidden inside the dex executable.
The latest example of spyware in Google Play disguised as a browser cleaner
The malicious payload APK is now packed in an encrypted file in the assets directory and is decrypted by the first stage using an AES algorithm.
all payloads across the different versions... share a code structure and locations where sensitive strings, such as С2 addresses, are stored.
53 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Android spyware/backdoor distributed via trojanized apps; collects geolocation, call logs, contacts, monitors SMS, and inventories device/app information.
Android malware/campaign attributed with medium confidence to OceanLotus; uses techniques to bypass app market filters and (in 2020 samples) Firebase to decrypt payloads.
Android spyware/backdoor campaign distributed via Google Play and third-party app marketplaces. It collects geolocation, call logs, contacts, SMS, installed apps, and device information, and can download and execute additional payloads. Later variants used encrypted staged payloads and Firebase remote config to obtain decryption keys.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.