Prizmes is described as a mobile trojan and one of the more common malware threats targeting mobile devices. According to the provided content, it typically spreads via untrusted app stores, links in scam messages, and other suspicious downloads. Once installed, it operates stealthily in the background and attempts to collect as much information as possible from the infected device.
Reported capabilities include reading messages, stealing or phishing login credentials, monitoring network traffic, downloading additional components to expand attacker access, exfiltrating stolen data to remote servers, and potentially using the infected device as part of a larger botnet. The content states that much of this activity can occur without the user’s knowledge, allowing infections to persist undetected for long periods.
Observed effects and indicators mentioned in the content include degraded device performance, unusually rapid battery drain, increased data usage without a clear reason, and risk to private user data. The malware is discussed in a Finnish National Cyber Security Centre weekly report (51/2025), but no specific threat actor, industry targeting, platform family, or concrete IOCs such as domains, hashes, or IP addresses are provided in the content.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 distinct techniques documented for this family, organized by ATT&CK tactic.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Prizmes is a trojan targeting mobile devices, designed to stealthily collect user information.
Mobile trojan that infects devices via untrusted app stores, scam-message links, or suspicious downloads. It operates stealthily in the background, collects device information, can read messages, phish credentials, monitor network traffic, download additional components, exfiltrate data to remote servers, and potentially use the device as part of a botnet.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.