Wibag is an Android spyware family discovered by ESET in Iraq. It masquerades as the YouTube app and has been observed targeting messaging and social media platforms including Telegram, WhatsApp, Instagram, Facebook, and Snapchat. Reported capabilities include keylogging and exfiltration of SMS messages, call logs, location data, contacts, screen recordings, and recordings of WhatsApp calls and regular phone calls. Supporting reporting also states that it collects messages, call logs, and location data, and that its admin panel or login screen displays branding associated with the Iraqi National Security Service logo. The available content identifies Wibag as part of an Android spyware operation appearing in Iraq; no additional high-confidence infection vector, industry targeting, or specific indicators of compromise are provided in the supplied material.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct techniques documented for this family, organized by ATT&CK tactic.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Android spyware masquerading as the YouTube app; collects messages, call logs, and location data and uses an Iraqi National Security Service-branded login screen for deception.
Android spyware masquerading as the YouTube app, targeting messaging and social media platforms for surveillance and data theft.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.