XLoader for Android is Android malware that has been observed masquerading as a security application to deceive users and reduce suspicion during installation. It is associated with mobile surveillance and data-harvesting behavior, particularly the collection of SMS messages and device-identifying information. Reported host profiling includes theft of subscriber and device identifiers such as IMSI, ICCID, Android ID, and serial number. These capabilities support victim fingerprinting, monitoring, and potential follow-on abuse of SMS-based authentication or communications. The available evidence supports Android targeting and information-stealing behavior, but does not establish additional capabilities beyond SMS and device identifier collection at high confidence.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
10 distinct techniques documented for this family, organized by ATT&CK tactic.
Domains used inside SMS messages are either registered with Godaddy or use dynamic dns services such as duckdns.org. The intrusion set uses more than hundreds subdomains.
AbstractEmu can collect device IP address and SIM information; Android/SpyAgent has collected device network information, such as the IMEI and the phone number; ANDROIDOS_ANSERVER.A gathers the device IMEI and IMSI; many listed mobile malware families collect IMEI, IMSI, ICCID, MEID, serial number, phone number, MAC address, IP address, carrier, MCC/MNC, and related device/network identifiers.
26 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
Other indicator types observed in public reporting.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Android loader that disguises itself as a security application.
Android malware that collects SMS messages from infected devices.
Android variant of XLoader that collects Android ID and serial number.
Android malware that collects Android ID and serial number from infected devices.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.