Android/Chuli.A is an Android malware family associated with mobile-device surveillance and data theft. It has been observed collecting contact list data from both handset storage and the SIM card, stealing SMS message content, harvesting call logs, and gathering basic device profiling information such as phone number, operating system version, device model, and SDK version. For command and control and data transfer, it uses HTTP-based uploads over standard application-layer web traffic. Reported delivery involves a spearphishing message carrying a malicious Android application attachment, indicating sideloaded installation outside normal app-store channels. The malware targets Android devices and exhibits behavior consistent with mobile spyware focused on victim communications and device reconnaissance.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct technique documented for this family, organized by ATT&CK tactic.
15 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Android malware that steals SMS message content from infected devices.
Mobile malware that used HTTP uploads to a URL for command and control.
Android trojan delivered through spearphishing with a malicious app attachment.
Android trojan/spyware that steals call log data from infected devices.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.