Agent Smith is an Android malware family known for repackaging and impersonating legitimate applications to gain a foothold on devices and then modifying installed apps. It disguises its core components as a legitimate Google application and has been observed using a weaponized legitimate application as a dropper, enabling it to blend into normal app ecosystems and reduce user suspicion. Distribution has been associated with third-party Android app stores rather than authorized marketplaces.
Once present on a device, Agent Smith performs application discovery by enumerating installed apps and checks whether targeted applications are running before attempting infection. Its behavior is geared toward selectively targeting popular applications on the device and impersonating them, combining initial-access tradecraft with defense evasion. It has also been observed deleting update packages for infected applications when those updates are detected, a mechanism that helps preserve the malicious modifications by preventing legitimate app updates from overwriting the infected versions.
The malware is associated with Android mobile environments and is notable for its use of masquerading, selective app targeting, process-aware infection logic, and file deletion to maintain control over compromised applications.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct techniques documented for this family, organized by ATT&CK tactic.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Android malware that impersonates popular apps and disguises itself as a legitimate Google application; delivered via a weaponized legitimate app bundle.
Android mobile malware that enumerates installed applications on the device.
Mobile malware distributed via a third-party Android app store.
Android malware that impersonates popular apps and disguises itself as a legitimate Google application; its dropper weaponized a legitimate app bundle.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.