CHEMISTGAMES is an Android malware family that has been observed masquerading as popular South Korean applications. It supports post-compromise surveillance and data theft functions, including collection of files from the device filesystem and theft of account information from Google Chrome. The malware also fingerprints infected devices to uniquely identify victims, indicating host profiling and victim tracking capability. For command and control, CHEMISTGAMES has used HTTPS, allowing its traffic to blend with normal encrypted web communications. The observed behavior is consistent with mobile espionage-oriented malware focused on covert collection of user data from compromised Android devices.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct techniques documented for this family, organized by ATT&CK tactic.
Anubis can exfiltrate files encrypted with the ransomware module from the device and can modify external storage. BusyGasper can collect images stored on the device and browser history. CHEMISTGAMES can collect files from the filesystem and account information from Google Chrome.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Android trojan that disguises itself as popular South Korean applications.
Android spyware that steals filesystem data and Chrome account information.
Mobile malware family that used HTTPS for command-and-control communication.
Android malware that steals filesystem data and Google Chrome account information.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.