Golden Cup is an Android surveillance malware family with spyware-like collection capabilities focused on harvesting user data and device metadata from compromised mobile devices. Observed functionality includes collecting installed application lists, contact lists, sent and received SMS messages, phone number and IMSI data, device profiling information such as serial number and product details, and media or attacker-selected files including images and videos. It also supports camera-based surveillance by taking pictures on the infected device. For command and control, Golden Cup has used standard application-layer protocols including HTTP as well as MQTT, allowing its traffic to blend with legitimate mobile and IoT-style network activity. The malware’s behavior is consistent with mobile espionage and broad device monitoring rather than a narrowly scoped banking-only payload.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
6 distinct techniques documented for this family, organized by ATT&CK tactic.
AbstractEmu can collect device IP address and SIM information; Android/SpyAgent has collected device network information, such as the IMEI and the phone number; ANDROIDOS_ANSERVER.A gathers the device IMEI and IMSI; many listed mobile malware families collect IMEI, IMSI, ICCID, MEID, serial number, phone number, MAC address, IP address, carrier, MCC/MNC, and related device/network identifiers.
Anubis can exfiltrate files encrypted with the ransomware module from the device and can modify external storage. BusyGasper can collect images stored on the device and browser history. CHEMISTGAMES can collect files from the filesystem and account information from Google Chrome.
Golden Cup has communicated with the C2 using MQTT and HTTP.
17 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Android malware that can take pictures using the camera.
Android malware that obtains a list of installed applications.
Android spyware that collects media and attacker-selected files.
Mobile spyware that collects both sent and received SMS messages.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.