CherryBlos is an Android malware family focused on cryptocurrency theft. It is designed to steal wallet-related credentials, harvest mnemonic phrases, and hijack cryptocurrency withdrawals by replacing destination addresses during transactions. The malware has been observed abusing Android Accessibility Services to monitor application activity, detect when wallet apps are launched, obtain permissions, and facilitate fraudulent user-interface interactions such as fake wallet or withdrawal screens. It also uses optical character recognition to extract sensitive wallet recovery information from images stored on the device.
CherryBlos communicates with command-and-control infrastructure over HTTPS and exfiltrates stolen credential material to its operators. The malware has been associated with phishing websites promoted through social media and Telegram channels, and has been distributed through trojanized Android applications, including apps themed around chat, mining, and financial lures. Reporting has also linked CherryBlos to broader scam-app activity involving shared infrastructure and signing artifacts with the related FakeTrade campaign, suggesting operation by the same threat actor.
The family employs defense-evasion and persistence measures, including packing, obfuscation, and anti-kill or anti-uninstall behavior. Observed targeting has been global, with localized applications aimed at users in multiple regions. CherryBlos is best characterized as an Android infostealer specializing in cryptocurrency wallet credential theft and transaction hijacking.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct techniques documented for this family, organized by ATT&CK tactic.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
... CherryBlos ... (v1.0) ...
Android credential-stealing malware targeting cryptocurrency-related accounts/assets.
CherryBlos (v1.0)
CherryBlos is an Android malware family designed to steal cryptocurrency wallet credentials and hijack withdrawal transactions by replacing wallet addresses. It uses advanced evasion techniques, including commercial packers, obfuscation, and abuse of Android Accessibility Services. It can also use OCR to extract mnemonic phrases from images stored on the device.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.