Hermit is a modular commercial spyware platform attributed by multiple security researchers to the Italian surveillance vendor RCS Lab and associated entity Tykelab. It targets mobile devices and has been documented on Android, with reporting also linking it to iOS. Hermit is designed for covert surveillance after installation, enabling operators to collect messages, call logs, contacts, photos, device location, and other sensitive data, record calls and ambient audio, and in some cases capture screen content. Its architecture supports post-deployment retrieval of additional modules, allowing capabilities to be expanded on demand while reducing the initial footprint.
On Android, Hermit has been observed impersonating telecommunications providers and smartphone brands, presenting benign-looking carrier or support pages while malicious activity runs in the background. Delivery has been associated with SMS-based lures and malicious links, and some operations reportedly involved social-engineering workflows in which victims were prompted to install applications masquerading as carrier or messaging software. Researchers also reported code and module behavior consistent with attempts to obtain elevated privileges on compromised devices, including use of root access to facilitate surveillance functions and manipulation of other applications.
Hermit includes anti-analysis measures such as emulator detection and integrity checks, and it authenticates transmitted data. Documented modules support collection from applications and device subsystems including address books, accounts, audio, browser data, calendars, camera access, clipboard contents, notifications, screen capture, and messaging applications such as Telegram and WhatsApp. The spyware has been linked to campaigns in Kazakhstan and Italy, with additional reporting indicating activity in Romania and likely targeting in northeastern Syria. Public reporting has described its use against high-profile individuals including journalists, activists, academics, business executives, and government officials. Hermit is part of the broader commercial surveillance ecosystem and has been cited as an example of spyware sold to government customers for lawful-intercept and intelligence purposes, with significant concern over abuse against civil society and political targets.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
At the same time, Tykelab’s parent company, RCS Lab, has developed a powerful phone hacking tool, Hermit, which once installed on a victim’s device can be used to remotely activate the phone’s microphone, as well as record calls, access messages, call logs, contacts, photos and other sensitive data.
Its surveillance products include Hermit, a phone-hacking tool that once installed on a device can be used to record calls and remotely access messages, call logs, contacts, photos, and other sensitive data.
26 distinct techniques documented for this family, organized by ATT&CK tactic.
These products, often referred to as spyware, range from software and tools that enable remote access to a computer system without the consent of the user, administrator, or owner of the computer system.
Google published details of a previously unknown but sophisticated hacking package called Hermit... and provided lists of fake internet domains which the company had set up to lure targets to download the software. They included domains masquerading as Apple and Facebook, as well various telecom providers.
With system access, intermediaries are able to collect, exploit, extract, intercept, retrieve, alter, delete, or transmit content.
Intermediaries are fundamentally different than other entities that operate within the marketplace for OCC. Intermediaries are largely found as partners within the OCC supply chain, complimenting product development through vulnerability research to complete exploit chains or as auxiliary support during technology deployment.
They included domains masquerading as Apple and Facebook, as well various telecom providers.
deleteApk Boolean indicating whether APK files should be deleted if anti-emulation checks fail.
Attackers were able to distribute infected apps on iOS by enrolling in Apple’s Developer Enterprise Program. This allowed bad actors to bypass the App Store’s standard vetting process and obtain a certificate that 'satisfies all of the iOS code signing requirements on any iOS devices.'
collect data such as call logs, contacts, photos, device location and SMS messages.
Its surveillance products include Hermit, a phone-hacking tool that once installed on a device can be used to record calls and remotely access messages, call logs, contacts, photos, and other sensitive data.
Screen Capture Take pictures of the screen. Use root to run ‘screencap’.
The first malicious step is to decrypt an embedded configuration file with properties that are used to communicate with the C2 server.
32 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Spyware sold via resellers on behalf of Hacking Team/Memento Labs.
A modular Android surveillanceware platform used in targeted campaigns, including in Kazakhstan and Syria, that impersonates legitimate telecom or smartphone-brand apps, performs anti-analysis checks, downloads capability modules on demand, and can collect contacts, SMS, call logs, photos, location, notifications, clipboard data, browser data, calendar data, audio, screen captures, and device information. It also supports APK download/install, abuse of root access, and functionality to facilitate Telegram and WhatsApp reinstallation for surveillance purposes.
Commercial spyware for Android and iPhone devices that enables remote surveillance, including microphone activation, call recording, and access to messages, call logs, contacts, photos, and other sensitive data.
Commercial spyware attributed to RCS Lab that infects mobile devices and enables remote surveillance, including microphone activation, call recording, and access to messages, contacts, photos, and other sensitive data.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.