RuMMS is an Android malware family delivered through SMS messages that direct victims to install a malicious APK outside official app-store channels. It is designed primarily to monitor and exfiltrate mobile text messages, uploading incoming SMS content to remote command-and-control infrastructure. The malware also performs device profiling by collecting identifiers and host metadata including the phone number, IMEI, device model, and operating system version, then transmitting that information to its operators. RuMMS communicates with its command-and-control servers over HTTP, blending malicious traffic with ordinary web activity. The observed behavior is consistent with mobile surveillance and fraud-enabling malware focused on Android devices, particularly where SMS access can be abused for monitoring communications or capturing one-time codes.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct techniques documented for this family, organized by ATT&CK tactic.
AbstractEmu can collect device IP address and SIM information; Android/SpyAgent has collected device network information, such as the IMEI and the phone number; ANDROIDOS_ANSERVER.A gathers the device IMEI and IMSI; many listed mobile malware families collect IMEI, IMSI, ICCID, MEID, serial number, phone number, MAC address, IP address, carrier, MCC/MNC, and related device/network identifiers.
FinFisher captures and exfiltrates SMS messages. FrozenCell has read SMS messages for exfiltration. Pallas captures and exfiltrates all SMS messages... Rotexy can also send a list of all SMS messages on the device to the command and control server. RuMMS uploads incoming SMS messages to a remote command and control server. Stealth Mango uploads SMS messages. Windshift has included SMS message exfiltration...
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Android malware family using HTTP for command and control.
Mobile trojan that uploads incoming SMS messages to a remote C2 server.
Android malware family attacking users via SMS phishing with APK download links.
Mobile malware that gathers device model and OS version information and sends it to C2 infrastructure.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.