Riltok is an Android banking malware family focused on credential theft and device data collection. It communicates with command-and-control infrastructure over HTTP and profiles infected devices by collecting details such as phone number, country, mobile operator, model, root status, operating system version, and IMEI. It can enumerate installed applications and compare them against an operator-defined target list, enabling selective targeting of banking or other high-value apps.
A core Riltok capability is SMS interception, which supports theft of one-time codes and other messages relevant to fraud workflows. It also accesses and uploads the victim’s contact list, which has been associated with further propagation activity. Riltok uses deceptive user-interface prompts to harvest financial information, including fake Google Play payment screens and spoofed mobile banking interfaces designed to solicit bank card and related user details.
Riltok is distributed through phishing SMS messages, including messages sent from already infected devices, making smishing a primary infection vector. The malware targets Android devices and is commonly characterized as mobile banking malware with credential-harvesting and surveillance functions.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
6 distinct techniques documented for this family, organized by ATT&CK tactic.
AbstractEmu can collect device IP address and SIM information; Android/SpyAgent has collected device network information, such as the IMEI and the phone number; ANDROIDOS_ANSERVER.A gathers the device IMEI and IMSI; many listed mobile malware families collect IMEI, IMSI, ICCID, MEID, serial number, phone number, MAC address, IP address, carrier, MCC/MNC, and related device/network identifiers.
In the log we can see that: A client 96.57.xx.xxx Sent a web request “GET tuneappservice.org/l3k42hj56h634gkj2lk14356jk4gh23k5jl6h4/gate.php?ped=RTY3M0E4NjhDQ0I5JE1DLTEwNw” We can see here what looks like a malware callback, it’s in fact Riltok.
Examples in the content include: 'Riltok can access and upload the device's contact list to the command and control server,' 'Rotexy can access and upload the contacts list to the command and control server,' and multiple entries stating malware can 'exfiltrate' contacts.
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
Other indicator types observed in public reporting.
15 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Android malware observed via callback traffic in BraZZZers logs, leaking victim and gate path information.
Mobile banking trojan that enumerates installed apps and compares them against a targeted list.
Android banking trojan that intercepts incoming SMS messages.
Android banking trojan that impersonates Google Play and banking app screens to steal payment card and banking details.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.