VajraSpy is an Android remote access trojan used in targeted mobile espionage campaigns and associated with the Patchwork threat group, also tracked by some vendors as APT-Q-43 or VajraEleph. It has been distributed through trojanized Android applications, including fake messaging and chat apps and at least one news-themed app, with some samples also reaching official app marketplaces. Reporting has linked its targeting primarily to users in Pakistan, including Pakistani military personnel, and to honey-trap style social-engineering operations.
VajraSpy supports broad surveillance and data-theft functions on compromised Android devices. Confirmed collection and exfiltration capabilities include contacts, SMS messages, call logs, device details, installed application lists, location data, notifications, and selected files from device storage. Some variants request external storage permissions and harvest files with specific extensions before exfiltration. More advanced variants abuse Android accessibility services and notification access to intercept communications from applications such as WhatsApp, WhatsApp Business, and Signal. Reported higher-end functionality also includes call recording, ambient audio recording, keystroke logging, taking photos, and Wi-Fi network scanning.
Operationally, VajraSpy has used legitimate cloud-backed mobile infrastructure, including Firebase services, for command-and-control support, message handling, and storage of stolen data. Some variants package harvested information into structured formats such as JSON and may temporarily store intercepted messaging data in local SQLite databases before upload. Its use of legitimate services and standard Android frameworks can complicate network-based detection and attribution.
VajraSpy is best characterized as an Android espionage RAT focused on persistent surveillance, collection, and exfiltration from mobile targets rather than overt disruption or monetization.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
In the background, these apps covertly execute remote access trojan (RAT) code called VajraSpy, used for targeted espionage by the Patchwork APT group.
In the background, these apps covertly execute remote access trojan (RAT) code called VajraSpy, used for targeted espionage by the Patchwork APT group.
In the background, these apps covertly execute remote access trojan (RAT) code called VajraSpy, used for targeted espionage by the Patchwork APT group.
In the background, these apps covertly execute remote access trojan (RAT) code called VajraSpy, used for targeted espionage by the Patchwork APT group.
We came across a twitter post that described one such incident involving VajraSpy, an Android RAT that uses a designated Google Cloud Storage to store the data stolen from the user. VajraSpy is used by APT-Q-43 (#VajraEleph) group targeting Pakistani military personnel.
8 distinct techniques documented for this family, organized by ATT&CK tactic.
DocSwap has checked for the WRITE_EXTERNAL_STORAGE permission. Drinik can request the READ_EXTERNAL_STORAGE and WRITE_EXTERNAL_STORAGE Android permissions. TangleBot can request permission to view files and media. VajraSpy has also requested for android.permission.WRITE_EXTERNAL_STORAGE and android.permission.READ_EXTERNAL_STORAGE.
Examples in the content include: 'Riltok can access and upload the device's contact list to the command and control server,' 'Rotexy can access and upload the contacts list to the command and control server,' and multiple entries stating malware can 'exfiltrate' contacts.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Android-targeted remote access trojan referenced as previously used by Dropping Elephant via fake downloadable apps.
Android espionage malware disguised in trojanized apps, mostly messaging apps. It exfiltrates contacts, files, call logs, SMS messages, device location, installed apps, and notifications; more capable variants can intercept WhatsApp, WhatsApp Business, and Signal messages, record calls and ambient audio, log keystrokes, take pictures, and scan Wi‑Fi networks. It uses Firebase-hosted infrastructure and HTTP/HTTPS C2 for data exfiltration.
Android spyware/RAT disguised as the chat app “Crazy Talk.” It abuses Firebase/Google Cloud Storage to upload stolen victim data, including contacts, SMS, call logs, WhatsApp and WhatsApp Business messages, Signal messages, device details, and installed app lists.
Spyware that requests storage permissions, collects selected file types, and exfiltrates them.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.