Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
CERT Polska в апреле 2026 года выложила разбор cifrat - трёхстадийного Android-дроппера, где внешний APK грузил нативную библиотеку, та расшифровывала второй APK под маской Google Play Services, а из него вылезал финальный RAT-модуль с WebSocket C2, стримом экрана и SOCKS5-туннелем.
24 distinct techniques documented for this family, organized by ATT&CK tactic.
CERT Polska analyzed a Booking themed Android malware chain delivered through phishing and a fake update website.
Место в цепочке атаки: supply chain через троянизированный SDK Атака через Compromise Software Supply Chain (T1195.002, Initial Access) ... Вместо прямого фишинга или сайдлоада злоумышленник компрометирует звено в цепочке разработки: SDK аналитики, рекламный модуль, библиотеку push-уведомлений.
The activity builds a WebView, exposes a JavaScript bridge... The bridge is active and not cosmetic. It fingerprints the victim device and can trigger the installation flow.
The outer APK decrypts res/raw/init_bundle_uzge.bin with a 32-byte XOR key... FH.svg is decrypted with an RC4-like routine keyed by mLYQ.
Defense Evasion - ... зашифрованный payload в нативной библиотеке скрывает вредоносный код от статического анализа (T1027.009)
The analyzed sample was delivered through a phishing chain that ended with a fake Booking Pulse application update page... the outer APK decrypts another embedded APK disguised as Google Play Services.
Collection - финальный RAT собирает ... файлы устройства (T1005)
Collection - финальный RAT собирает SMS, контакты, нажатия клавиш (T1056.001)
The sample is a multistage dropper that installs a hidden accessibility controlled RAT with WebSocket C2.
The malware module also exposes a SOCKS5 tunnel controlled through the C2 infrastructure... Enabling SOCKS5 tunnel to ...
15 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Three-stage Android dropper that loads a native library to decrypt a second APK disguised as Google Play Services, which then deploys a final RAT module with WebSocket C2, screen streaming, and a SOCKS5 tunnel.
Android malware delivered via phishing and a fake update website. It operates as a multistage dropper that installs a hidden RAT controlled through accessibility features and communicates with C2 over WebSocket.
A multi-stage Android malware chain delivered via fake Booking.com update pages. The outer APK decrypts and installs a second-stage APK, which decrypts a hidden final payload. The final payload is an accessibility-controlled RAT with overlay injection, SMS theft, screen streaming, camera capture, keylogging, remote gestures, device manipulation, and SOCKS5 tunneling over dual WebSocket C2 channels.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.