Corona Updates is an Android surveillance malware family with broad data-collection and remote-control capabilities consistent with mobile spyware or a remote access trojan. It communicates with command-and-control infrastructure over HTTP and has been documented exfiltrating stolen data via FTP. Its collection features include SMS messages, call logs, contacts, device accounts, gallery images, voice notes, and device profiling data such as operating system version, phone model, manufacturer, Wi‑Fi SSID, and IMSI. It can also harvest message content from applications including WhatsApp, Telegram, Facebook, Threema, and GSM messaging by reading notification content.
The malware supports active surveillance functions beyond passive collection. It can send SMS messages, take pictures with the device camera, record MP4 video, and monitor calls. These capabilities indicate use for covert monitoring, data theft, and ongoing post-compromise access on infected mobile devices. The observed behavior aligns with espionage-oriented Android malware that abuses standard mobile permissions and application-layer network protocols to blend malicious traffic with normal device activity.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct techniques documented for this family, organized by ATT&CK tactic.
AbstractEmu can collect device IP address and SIM information; Android/SpyAgent has collected device network information, such as the IMEI and the phone number; ANDROIDOS_ANSERVER.A gathers the device IMEI and IMSI; many listed mobile malware families collect IMEI, IMSI, ICCID, MEID, serial number, phone number, MAC address, IP address, carrier, MCC/MNC, and related device/network identifiers.
Anubis can exfiltrate files encrypted with the ransomware module from the device and can modify external storage. BusyGasper can collect images stored on the device and browser history. CHEMISTGAMES can collect files from the filesystem and account information from Google Chrome.
24 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Android malware capable of taking pictures and recording MP4 video files.
Malicious mobile app/spyware family able to send SMS messages.
Android spyware that steals voice notes, account data, and gallery images.
Android trojan that collects SMS messages.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.