RedDrop is an Android mobile spyware family known for distributing malicious applications outside official app stores through advertisements and links on websites, using redirect chains and content distribution infrastructure to entice users into sideloading infected apps. It can also retrieve additional components after installation, including further application packages and Java-based modules, expanding functionality post-compromise.
RedDrop is associated with surveillance and data-theft behavior on infected devices. It captures live audio recordings from the device’s surroundings and collects extensive device, subscriber, and network profiling data, including mobile subscriber identifiers, carrier and country codes, nearby Wi-Fi information, and operating system and manufacturer details. The malware transmits stolen information to command-and-control infrastructure and uses standard HTTP both for command-and-control communications and for exfiltration, allowing its traffic to blend with ordinary web activity.
The malware’s observed behavior aligns with Android-focused spyware that combines social-engineering-based installation, host profiling, audio collection, modular payload retrieval, and network-based data theft. Its use of sideloaded malicious apps and follow-on component downloads makes it particularly relevant to mobile threat defense, enterprise mobility management, and investigations involving unauthorized Android application installation and covert surveillance.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 distinct techniques documented for this family, organized by ATT&CK tactic.
AbstractEmu can collect device IP address and SIM information; Android/SpyAgent has collected device network information, such as the IMEI and the phone number; ANDROIDOS_ANSERVER.A gathers the device IMEI and IMSI; many listed mobile malware families collect IMEI, IMSI, ICCID, MEID, serial number, phone number, MAC address, IP address, carrier, MCC/MNC, and related device/network identifiers.
PJApps has the capability to collect and leak the victim's phone number, mobile device unique identifier (IMEI); RedDrop collects and exfiltrates information including IMEI, IMSI, MNC, MCC, nearby Wi‑Fi networks, and other device and SIM-related info; Sunbird can exfiltrate phone number and IMEI; WolfRAT sends the device’s IMEI with each exfiltration request.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mobile malware family using standard HTTP for both communication and data exfiltration.
Mobile malware family spread via ads and website links with redirect chains; downloads additional APK and JAR components from C2 servers.
Mobile malware family that records ambient audio from a victim's surroundings.
Android malware that exfiltrates device operating system and manufacturer details.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.