SilkBean is an Android surveillance malware family described as a surveillance tool with extensive remote access trojan (RAT) features. The content links it to the China-aligned threat activity of APT15 and also notes alignment with targeting associated with GREF. It was used in campaigns targeting the Uyghur ethnic minority, including activity noted in 2015 alongside other Android surveillanceware families such as DoubleAgent, CarbonSteal, and GoldenEagle.
Documented capabilities include accessing and sending SMS messages, accessing call logs, accessing device contacts, retrieving files from external storage, collecting browser data, and accessing the device camera. The content also states SilkBean has used HTTPS for command-and-control communication, and more generally places it among Android malware families using HTTP/HTTPS or related application-layer channels for C2.
High-confidence associations in the content include APT15 use of Android spyware SilkBean, with APT15 also tracked under aliases including Nickel, Ke3Chang, and Vixen Panda. The reporting describes APT15 as a China-based cyber espionage group that has targeted government, diplomatic, and military sectors globally, while SilkBean specifically appears in the context of mobile surveillance against Uyghur targets. No specific file hashes or other unique IoCs for SilkBean are provided in the supplied content.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
This aligns with the targeting of other Android trojans previously used by GREF (BadBazaar, SilkBean, DoubleAgent, CarbonSteal, and GoldenEagle).
3 distinct techniques documented for this family, organized by ATT&CK tactic.
AbstractEmu can collect files from or inspect the device’s filesystem. AhRat can find and exfiltrate files with certain extensions, such as .jpg, .mp4, .html, .docx, and .pdf. BOULDSPY can access browser history and bookmarks, and can list all files and folders on the device.
15 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
SilkBean is an Android surveillanceware used by APT15 to monitor and collect information from targeted mobile devices, particularly in espionage campaigns.
Android surveillance malware with extensive RAT capabilities used for remote access and spying.
Android trojan previously used by GREF and mentioned as part of overlapping targeting against Uyghurs and other Turkic minorities.
Android spyware attributed to APT15 (mentioned as part of the group’s tooling).
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.