Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
17 distinct techniques documented for this family, organized by ATT&CK tactic.
Каждый SDK - потенциальный вектор supply chain атаки... Атакующий модифицирует SDK так, чтобы он выполнял легитимные функции, параллельно собирая данные или предоставляя удалённый доступ.
Место в цепочке атаки: supply chain через троянизированный SDK Атака через Compromise Software Supply Chain (T1195.002, Initial Access) ... Вместо прямого фишинга или сайдлоада злоумышленник компрометирует звено в цепочке разработки: SDK аналитики, рекламный модуль, библиотеку push-уведомлений.
The malware uses a "Byte-Reversal" trick on APK payloads.
Defense Evasion - ... зашифрованный payload в нативной библиотеке скрывает вредоносный код от статического анализа (T1027.009)
Collection - финальный RAT собирает ... файлы устройства (T1005)
Key findings include a Remote Access Trojan capable of loading arbitrary code, detailed event logging/spyware, and ad injection components - all running with SYSTEM privileges.
a persistent RAT (SilentSDK) that communicates with a C2 server in China (api.pixelpioneerss.com).
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Described as a remote access trojan embedded inside a legitimate mobile SDK/library, representing a supply-chain attack vector.
A composite/sample name for a trojanized mobile SDK scenario built from documented techniques of cifrat and TaxiSpy, delivering a hidden RAT via software supply chain compromise.
A persistent remote access trojan/backdoor factory-installed on cheap Android projectors. The analysis describes C2 communications, remote command execution, chmod 777 on secondary payloads, deep device fingerprinting, and use of a custom TrustManager to bypass SSL validation.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.