BOULDSPY is an Android surveillance malware family used for mobile espionage and device monitoring. It has been described as a surveillance tool used by Iran’s law enforcement organization FARAJA. The malware is designed to collect and exfiltrate a broad range of victim data from compromised Android devices, including contacts, SMS logs, call logs, cached data, browser history, bookmarks, device identifiers, Android version information, and network-related information such as SIM and Wi-Fi details. It can also enumerate files and folders on the device, supporting broader on-device reconnaissance and data collection. BOULDSPY communicates with command-and-control infrastructure over unencrypted HTTP, indicating a relatively straightforward application-layer C2 design. Its observed behavior is consistent with spyware focused on persistent surveillance, victim profiling, and exfiltration of personal and device-resident information from Android targets.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
6 distinct techniques documented for this family, organized by ATT&CK tactic.
AbstractEmu can collect device IP address and SIM information; Android/SpyAgent has collected device network information, such as the IMEI and the phone number; ANDROIDOS_ANSERVER.A gathers the device IMEI and IMSI; many listed mobile malware families collect IMEI, IMSI, ICCID, MEID, serial number, phone number, MAC address, IP address, carrier, MCC/MNC, and related device/network identifiers.
AbstractEmu can collect files from or inspect the device’s filesystem. AhRat can find and exfiltrate files with certain extensions, such as .jpg, .mp4, .html, .docx, and .pdf. BOULDSPY can access browser history and bookmarks, and can list all files and folders on the device.
Examples in the content include: 'Riltok can access and upload the device's contact list to the command and control server,' 'Rotexy can access and upload the contacts list to the command and control server,' and multiple entries stating malware can 'exfiltrate' contacts.
18 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Surveillance tool reported in 2023 and described as used by Iran’s law enforcement (FARAJA).
Other documented malware strains include AridSpy, BouldSpy, GuardZoo, RatMilad, and SpyNote.
Android spyware that accesses browser data and enumerates files and folders on the device.
Spyware that accesses browser data and enumerates files and folders on the device.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.