Exodus is a modular surveillance malware family with Android components commonly designated Exodus One and Exodus Two, as well as reported Windows artifacts. On Android, Exodus One profiles newly infected devices by querying the IMEI and telephone number and checks in to command-and-control infrastructure via HTTP POST. Exodus Two performs extensive device surveillance and data collection, including address-book acquisition, call-log and SMS capture, enumeration of installed applications, collection of gallery metadata, browser bookmarks, and connected Wi-Fi passwords, and audio recording through the microphone and telephone calls. It can also capture images using device cameras. Reported Windows components provide file-management, SOCKS proxy, command-execution, scripting, browser-interaction, and VNC remote-control functionality, and use a deceptive installed-application identity. Android activity is consistent with spyware designed for persistent surveillance and data exfiltration.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
13 distinct techniques documented for this family, organized by ATT&CK tactic.
AbstractEmu can collect device IP address and SIM information; Android/SpyAgent has collected device network information, such as the IMEI and the phone number; ANDROIDOS_ANSERVER.A gathers the device IMEI and IMSI; many listed mobile malware families collect IMEI, IMSI, ICCID, MEID, serial number, phone number, MAC address, IP address, carrier, MCC/MNC, and related device/network identifiers.
Anubis can exfiltrate files encrypted with the ransomware module from the device and can modify external storage. BusyGasper can collect images stored on the device and browser history. CHEMISTGAMES can collect files from the filesystem and account information from Google Chrome.
54 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
22 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A modular remote-access backdoor/spyware implant. The listed modules indicate capabilities for file management, SOCKS proxying, command execution, scripting, browser interaction, and VNC-based remote desktop access.
Android malware variant capable of taking pictures with device cameras.
Android spyware capable of obtaining a list of installed applications.
Mobile spyware family whose Exodus Two variant can capture SMS messages.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.