Android/AdDisplay.Ashas is an Android malware family associated with deceptive adware-like behavior and device profiling. It has been observed collecting host metadata including device type, operating system version, language, available storage, battery status, root status, and whether developer mode is enabled. It also performs application discovery, including checking how many applications are installed and specifically whether Facebook or Facebook Messenger are present, indicating interest in victim profiling and app-aware behavior.
The malware communicates with command-and-control infrastructure over HTTP and uses Android broadcast receivers for persistence, registering for device boot events so it can activate automatically after startup. It also employs defense-evasion and masquerading techniques by imitating trusted brands in the recent-apps view and by using package naming intended to resemble legitimate Google software, reducing the likelihood of user discovery or casual inspection.
Android/AdDisplay.Ashas targets Android devices and combines persistence, reconnaissance, and network-based post-compromise communication with visual impersonation to maintain access and avoid detection.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct techniques documented for this family, organized by ATT&CK tactic.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Android adware family noted here for using HTTP for command-and-control communication.
Android adware that uses the BOOT_COMPLETED broadcast intent to activate when the device starts.
Android adware that mimics trusted app icons and Google-like package names to evade user suspicion and detection.
Android adware that checks installed apps, including specific social media applications.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.