Mamont is an Android banking malware family that emerged in late 2023 and became one of the most prevalent mobile banking threats observed through 2024–2026, especially in Russia and other CIS markets. It is commonly classified as a banking Trojan, although some packed variants have also been detected as droppers because operators increasingly use multi-stage installation chains and encrypted payloads.
Mamont is distributed through social-engineering lures rather than exploit-driven infection. Documented campaigns used fake parcel-tracking applications, fraudulent shopping and wholesale-goods offers, neighborhood chat scams, and other deceptive APK delivery schemes. Victims are persuaded to sideload an Android application presented as a legitimate utility or service, after which the malware requests extensive permissions related to SMS, calls, notifications, and background execution. Some variants act as droppers that decrypt and install a second-stage APK, reflecting modular design and defense-evasion tradecraft.
Once active, Mamont focuses on theft and fraud against mobile banking users. Reported capabilities include interception and forwarding of SMS messages and push notifications, including one-time codes and transaction confirmations; collection of device and subscriber information; harvesting of financial data from messages; remote command execution to send SMS messages, place calls, and issue USSD requests; and user-interface prompts designed to trick victims into submitting additional data. Certain variants can hide or alter their app icon, retrieve recent SMS history, and collect photos or other user-supplied content to support follow-on social engineering and account abuse.
Mamont has shown localized targeting and language adaptation. Campaigns have targeted Android users in Russia, including schemes aimed at consumers and small businesses, while other analyzed variants used Uzbek-language lures and parsed financial SMS content in Uzbek, Russian, and English. Across multiple reporting periods, Mamont variants consistently dominated mobile banking Trojan detections and real-world attack telemetry, indicating active development and sustained operational use.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
19 distinct techniques documented for this family, organized by ATT&CK tactic.
The app’s flow is designed to silently install this second APK and immediately launch its MainActivity.
the command and control (C2) server, whose address (http://84.21.189.36:2288) is stored base64encoded within the code
The attackers would then send what appeared to be the photo itself but was actually a malware installer... In reality, this was malware with no parcel-tracking functionality whatsoever.
Once installed, the primary app extracts an embedded file named data.bin from res/raw/ and decrypts it into a second APK.
When the app receives that command, the user sees a window with a text box for entering data, which is then sent to the command-and-control server.
The malware gathers sensitive device information, including installed apps, phone numbers, and operator/SIM details
It then asks the victim to enter the tracking number previously received from the scammers, and sends a POST request containing device information along with the number to the C2 server... The other one sets up a connection with the attackers’ WebSocket server.
9 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
16 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Android banking Trojan family that dominated real-world attack metrics in Q2 2026; newer variants rose sharply, and some packed banking samples were reclassified as droppers.
Active Android banking trojan family with multiple new variants dominating real-world attacks on users; some samples are also classified as droppers, indicating packaging and delivery changes.
Android banking malware family with multiple active variants dominating victim telemetry; newer variants rose sharply, and some packed samples were reclassified as droppers, indicating ongoing development and tactic shifts.
An Android malware variant discussed in the context of advanced dropper logic and an encrypted payload.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.