CarbonSteal is an Android surveillance malware family associated in the provided content with the China-aligned threat groups GREF and APT15. It is described as one of several Android trojans/surveillanceware families used in campaigns targeting the Uyghur ethnic minority, alongside SilkBean, DoubleAgent, BadBazaar, and GoldenEagle. Reported capabilities include collecting device metadata such as model, manufacturer, SD card size, disk usage, memory, CPU, and serial number; harvesting cellular network information including GSM Cell Identity, Location Area Code, Mobile Country Code (MCC), and Mobile Network Code (MNC); calling netcfg to obtain network statistics; and accessing SMS and MMS messages on the device. The content places CarbonSteal in 2015-era targeting of Uyghurs and notes it as part of broader GREF-linked Android malware activity.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
This aligns with the targeting of other Android trojans previously used by GREF (BadBazaar, SilkBean, DoubleAgent, CarbonSteal, and GoldenEagle).
1 distinct technique documented for this family, organized by ATT&CK tactic.
AbstractEmu can collect device IP address and SIM information; Android/SpyAgent has collected device network information, such as the IMEI and the phone number; ANDROIDOS_ANSERVER.A gathers the device IMEI and IMSI; many listed mobile malware families collect IMEI, IMSI, ICCID, MEID, serial number, phone number, MAC address, IP address, carrier, MCC/MNC, and related device/network identifiers.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
CarbonSteal is an Android surveillanceware used by APT15 to collect sensitive information from mobile devices.
Trojan referenced as one of the malware families previously used by GREF in similar targeting.
Software changes: CarbonSteal
Mobile malware that gathers extensive device metadata including hardware, storage, memory, CPU, and serial number details.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.