Hornbill is an Android surveillanceware family associated with the Confucius threat actor, a pro-India espionage group known for targeting Pakistani and other South Asian entities. It has been used against individuals linked to Pakistan’s military and nuclear sectors as well as election-related targets in Kashmir. Hornbill appears to have been active by 2018 and remained in use through at least late 2020.
Hornbill is designed for covert collection and selective exfiltration of victim data rather than overt destructive activity. It can gather device contacts, call logs, phone number, IMEI, device identifiers, model, manufacturer, Android version, storage information, and screen-lock status. It can also check device state such as whether Wi‑Fi is enabled, access images stored on external storage, and monitor location changes. The malware closely monitors WhatsApp-related activity and has been reported to record WhatsApp calls through abuse of Android accessibility services. It also monitors documents on external storage and tracks file activity.
The malware communicates with command-and-control infrastructure over HTTP, including HTTP POST, and exfiltrates collected data to remote servers. Its operational design emphasizes stealth and efficiency: it uploads data initially and then only when monitored information changes, reducing battery and mobile-data usage. Hornbill stores collected data in hidden locations on external storage and deletes locally gathered files after successful upload to reduce suspicion and hinder forensic recovery.
Hornbill has been assessed as derived from the MobileSpy commercial surveillanceware code base. Samples have impersonated chat and system-themed Android applications and were observed outside official app-store distribution. Overall, Hornbill is best characterized as Android spyware used for targeted mobile surveillance, reconnaissance, and data theft in support of espionage operations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Hornbill can delete locally gathered files after uploading them to the C2 to avoid suspicion.
11 distinct techniques documented for this family, organized by ATT&CK tactic.
AbstractEmu can collect files from or inspect the device’s filesystem. AhRat can find and exfiltrate files with certain extensions, such as .jpg, .mp4, .html, .docx, and .pdf. BOULDSPY can access browser history and bookmarks, and can list all files and folders on the device.
16 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
16 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Android surveillanceware used for discreet reconnaissance and selective data theft. It exfiltrates call logs, contacts, device metadata, geolocation, images, WhatsApp voice notes, screenshots, photos, audio recordings, WhatsApp messages/notifications, and monitors document activity. It uploads initial and changed data only, likely to reduce battery and data usage and avoid suspicion.
Android malware that accesses images on external storage.
Malware that accesses images stored on external storage.
Malware that accesses images stored on external storage.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.