Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
8 distinct techniques documented for this family, organized by ATT&CK tactic.
The database also contained 473,211 records of photos and videos uploaded from compromised phones during the six weeks, including screenshots, photos received from messaging apps and saved to the camera roll, and filenames, which can reveal information about the file.
The database also contained 454,641 records of data siphoned from the user’s keyboard, known as a keylogger, which included sensitive credentials and codes pasted from password managers and other apps.
The database is about 34 gigabytes in size and consists of metadata... including passwords and two-factor authentication codes... The database also contained 454,641 records of data siphoned from the user’s keyboard, known as a keylogger, which included sensitive credentials and codes pasted from password managers and other apps.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A stalkerware-type app mentioned as a prior example of software exposing victim data through an IDOR vulnerability.
A consumer spyware/stalkerware app; the content highlights an account-takeover weakness in its password recovery flow enabling access to victim data collected by the app.
Android stalkerware/spyware planted by someone with physical access to a victim’s device. It hides from the home screen and continuously exfiltrates phone contents, including call logs, text messages, granular location data, clipboard contents, Wi-Fi network names, photos/videos metadata, call recordings, and keylogged data.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.