AbstractEmu is an Android malware family notable for combining trojanized app distribution with on-device privilege escalation and rooting. It was distributed through official and third-party Android app marketplaces while masquerading as benign utility or system applications such as launchers, password managers, file managers, and data-saving tools. After execution, it performs anti-emulation and environment checks, profiles the device, and communicates with command-and-control infrastructure over HTTP using JSON-based tasking. AbstractEmu has been observed exploiting multiple Android vulnerabilities, including CVE-2020-0041, CVE-2020-0069, and modified public exploit code related to CVE-2019-2215, to obtain elevated privileges across a broader range of devices.
Once rooted, AbstractEmu can silently install a secondary application and grant it extensive permissions without meaningful user interaction. Documented capabilities include collection of device metadata, SIM and network information, filesystem inspection and file collection, access to contacts and call logs, interception of SMS messages including two-factor authentication codes, and exfiltration of large volumes of victim data to its operators. The malware also modifies device settings to weaken security controls and facilitate further abuse. Victims were observed across multiple countries, and the operation appeared broadly distributed rather than narrowly targeted. The operators have been assessed as likely financially motivated and comparatively well resourced, although the ultimate follow-on payload objective was not conclusively established because relevant command-and-control endpoints were unavailable at the time of analysis.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
One of the exploits used CVE-2020-0041, a vulnerability not previously seen exploited in the wild by Android apps. As a hint to the threat actor’s technical abilities, they also modified publicly available exploit code for CVE-2019-2215 and CVE-2020-0041 in order to add support for more targets. | Security researchers at Lookout have identified a new rooting malware distributed on Google Play and prominent third-party stores such as the Amazon Appstore and the Samsung Galaxy Store. We named the malware “AbstractEmu” after its use of code abstraction and anti-emulation checks to avoid running while under analysis.
As a hint to the threat actor’s technical abilities, they also modified publicly available exploit code for CVE-2019-2215 and CVE-2020-0041 in order to add support for more targets. | Security researchers at Lookout have identified a new rooting malware distributed on Google Play and prominent third-party stores such as the Amazon Appstore and the Samsung Galaxy Store. We named the malware “AbstractEmu” after its use of code abstraction and anti-emulation checks to avoid running while under analysis.
Another exploit targeted CVE-2020-0069, a vulnerability found in MediaTek chips used by dozens of smartphone manufacturers that have collectively sold millions of devices. | Security researchers at Lookout have identified a new rooting malware distributed on Google Play and prominent third-party stores such as the Amazon Appstore and the Samsung Galaxy Store. We named the malware “AbstractEmu” after its use of code abstraction and anti-emulation checks to avoid running while under analysis.
12 distinct techniques documented for this family, organized by ATT&CK tactic.
At the center of AbstractEmu’s infection flow is getting root access to the Android device... One of the exploits used CVE-2020-0041... Another exploit targeted CVE-2020-0069... they also modified publicly available exploit code for CVE-2019-2215 and CVE-2020-0041 in order to add support for more targets.
the app will send a large amount of data to the C2 server... device data such as the device’s manufacturer, model, version and serial number, telephone number and IP address.
AbstractEmu can collect files from or inspect the device’s filesystem. AhRat can find and exfiltrate files with certain extensions, such as .jpg, .mp4, .html, .docx, and .pdf. BOULDSPY can access browser history and bookmarks, and can list all files and folders on the device.
the app will begin communicating with its command and control (C2) server via HTTP, expecting to receive a series of JSON commands to execute.
18 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
.NET Stubs: Sowing the Seeds of Discord (PureCrypter) Aberebot AbstractEmu AdoBot 404 Keylogger Agent Tesla Amadey AsyncRAT Ave Maria BitRAT BluStealer Formbook LimeRAT Loki Password Stealer (PWS) Nanocore RAT Orcus RAT Quasar RAT Raccoon RedLine Stealer WhisperGate
Android rooting malware disguised as legitimate utility and system apps. It performs anti-emulation checks, communicates with a C2 server for JSON commands, exploits multiple Android vulnerabilities to gain root, installs Magisk components for persistent privileged access, silently installs a secondary app, grants intrusive permissions, modifies device security settings, and enables phishing, surveillance, and account-compromise activity.
Android malware that can inspect the filesystem and collect files from the device.
Android malware that can inspect the device filesystem and collect files.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.