Heliconia is an exploitation framework linked by Google Threat Analysis Group (TAG) to the Barcelona-based commercial spyware vendor Variston IT. Google reported that the framework enables spyware installation on targeted devices and comprises at least three exploit frameworks: a Chrome exploit chain that abuses a renderer bug to escape the browser sandbox and execute malware on the host OS, a malicious PDF chain exploiting Microsoft Defender on Windows, and a Firefox exploit framework targeting Windows and Linux. Google said the Firefox component affected Firefox versions 64 through 68, suggesting possible use as early as December 2018. TAG stated it had not directly observed Heliconia exploitation in the wild at the time of its 2022 disclosure, but assessed the vulnerabilities were likely first used as zero-days and later as n-days before Google, Microsoft, and Mozilla patched them in 2021 and 2022.
Subsequent reporting tied Heliconia infrastructure and landing pages to additional spyware operations. Google reported that a December 2022 campaign targeting users in the United Arab Emirates used one-time SMS links leading to a landing page identical to one previously examined in the Heliconia framework. That Android exploit chain targeted Samsung Internet Browser and used multiple vulnerabilities, including CVE-2022-4262, CVE-2022-3038, CVE-2022-22706, and CVE-2023-0266, ultimately installing a fully featured C++ Android spyware suite with libraries for decrypting and capturing data from chat and browser applications. Related indicators included the domains www.sufficeconfigure[.]com and www.anglesyen[.]org, and Android system properties sys.brand.note, sys.brand.notes, and sys.brand.doc. Google assessed the operator may have been a Variston customer, partner, or close collaborator.
Google also reported that in March 2023 a government customer used Variston tooling against iPhone users in Indonesia via SMS messages containing malicious links. After infection, victims were redirected to a legitimate Pikiran Rakyat news article. Google further stated that UAE-based Protect Electronic Systems combined spyware it develops with Variston’s Heliconia framework and infrastructure into packages sold to brokers or directly to government customers.
High-confidence associations in the content connect Heliconia to the commercial spyware market and to surveillance use against targeted individuals. The reporting places Variston alongside other commercial surveillance vendors and notes that such tooling has been linked broadly to surveillance of journalists, dissidents, politicians, and other high-risk users. The content does not provide a standalone Heliconia malware payload family name beyond the framework itself, but consistently describes Heliconia as the exploit and delivery framework used to install spyware on Windows, Linux, Android, and iPhone targets through browser, PDF, and SMS-delivered malicious-link vectors.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
6 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
"...a landing page identical to the one TAG examined in the Heliconia framework ... developed by commercial spyware vendor Variston."
"...a landing page identical to the one TAG examined in the Heliconia framework ... developed by commercial spyware vendor Variston."
"...a landing page identical to the one TAG examined in the Heliconia framework ... developed by commercial spyware vendor Variston."
"...a landing page identical to the one TAG examined in the Heliconia framework ... developed by commercial spyware vendor Variston."
"...a landing page identical to the one TAG examined in the Heliconia framework ... developed by commercial spyware vendor Variston."
"...a landing page identical to the one TAG examined in the Heliconia framework ... developed by commercial spyware vendor Variston."
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Вендор Продукт Целевые ОС Zero-click Страна ... Variston IT Heliconia Несколько Нет данных Испания
10 distinct techniques documented for this family, organized by ATT&CK tactic.
The hackers delivered an SMS text message containing a malicious link that infected the target’s phone with spyware, and then redirected the victim to a news article by the Indonesian newspaper Pikiran Rakyat.
Heliconia comprises three separate exploitation frameworks: one that contains an exploit for a Chrome renderer bug that allows it to escape the walls of the app’s sandbox to run malware on the operating system; another that deploys a malicious PDF document containing an exploit for Windows Defender... and another framework that contains a set of Firefox exploits for Windows and Linux machines.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Commercial surveillance tool from Variston IT targeting multiple platforms, mentioned within the spyware vendor ecosystem.
An exploitation framework attributed by Google TAG to Variston, containing (at the time) zero-day exploits used to target Chrome, Firefox, and PCs running Microsoft Defender; also described as being combined with spyware and infrastructure by Protect into a package sold to brokers/government customers.
A spyware and exploit delivery framework developed by Variston and combined with additional spyware and infrastructure for sale to government customers.
A commercial exploit framework (attributed here to Variston) referenced as having a landing page infrastructure similar to the one used in this Samsung Internet Browser exploit chain delivery.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.