Desert Scorpion is a custom Android spyware implant associated with the Desert Falcons threat actor and used in targeted surveillance operations. It is designed for espionage on Android devices and supports broad collection of victim data and device profiling. Observed capabilities include retrieving SMS messages, sending SMS messages, collecting the device contact list, enumerating installed applications, gathering device metadata, checking whether the device is rooted, recording video, and collecting attacker-specified files including content stored on external storage. The malware also includes a self-deletion behavior in which it can remove copies of itself if additional Android application packages are downloaded to external storage. Its functionality is consistent with mobile surveillance tooling intended to monitor victims, harvest sensitive personal and operational data, and support follow-on targeting decisions by operators.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
the custom-made Android spyware used by Desert Falcons is called Desert Scorpion
2 distinct techniques documented for this family, organized by ATT&CK tactic.
Bahamut... employed various malware for Software Discovery, particularly to gather a list of active processes, identify installed software, and check for specific antivirus programs (T1518.001)... Desert Scorpion... view... installed apps (Software Discovery).
Anubis can exfiltrate files encrypted with the ransomware module from the device and can modify external storage. BusyGasper can collect images stored on the device and browser history. CHEMISTGAMES can collect files from the filesystem and account information from Google Chrome.
16 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Android spyware capable of recording calls and microphone audio, tracking location, and accessing contacts, messages, and installed apps.
Android malware capable of recording video.
Mobile surveillance malware capable of enumerating installed applications.
Android surveillance malware with SMS-sending capability.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.