Pallas is an Android mobile remote-access trojan associated with the Lebanon-linked Dark Caracal threat group. It has been distributed in trojanized Android applications hosted on watering-hole websites, including in campaigns targeting Lebanese citizens. Pallas performs extensive device surveillance and data theft: it collects contacts, call logs, installed-application inventories, device metadata, and all SMS messages, including subsequently received messages. It can capture microphone audio and photographs using either front- or rear-facing cameras. Collected data is exfiltrated over HTTP. Pallas also presents phishing popups to harvest user credentials, can download and install attacker-specified applications, and can delete attacker-specified files, enabling additional compromise, operational control, and removal of selected artifacts.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The group has also employed custom malware like Pallas and a modified version of the Bandook remote access trojan.
6 distinct techniques documented for this family, organized by ATT&CK tactic.
Cerberus has been delivered to the device via websites that prompt the user to "[…] install Adobe Flash Player" and then downloads the malicious APK to the device. | Dark Caracal distributes Pallas via trojanized applications hosted on watering hole websites.
FinFisher captures and exfiltrates SMS messages. FrozenCell has read SMS messages for exfiltration. Pallas captures and exfiltrates all SMS messages... Rotexy can also send a list of all SMS messages on the device to the command and control server. RuMMS uploads incoming SMS messages to a remote command and control server. Stealth Mango uploads SMS messages. Windshift has included SMS message exfiltration...
21 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Custom malware previously employed by Dark Caracal; no further functional details are provided.
Pallas is described as a mobile remote access trojan previously used in Dark Caracal campaigns.
Android malware that can capture images using both front and rear cameras.
Android malware that uses phishing popups to steal user credentials.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.