ViceLeaker is an Android surveillance malware family with broad on-device collection and exfiltration capabilities. It has been observed embedded into otherwise legitimate Android applications through Smali injection and distributed primarily through messaging platforms such as Telegram and WhatsApp, aligning with a trojanized-app delivery model.
Its functionality includes collecting SMS messages, harvesting call logs, enumerating installed applications, copying arbitrary files from the device, exfiltrating browsing history and SD card structure, and capturing pictures as they are taken. It also supports active surveillance through recording audio from the microphone, recording phone calls together with caller ID, and taking photos with both the front and rear cameras. In addition, it can delete arbitrary files from the device, indicating both collection and defense-evasion or cleanup capability.
ViceLeaker communicates with command-and-control infrastructure and exfiltrates stolen data over HTTP. The malware is associated with post-compromise mobile espionage behavior focused on persistent monitoring and theft of locally stored and user-generated data from infected Android devices.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
7 distinct techniques documented for this family, organized by ATT&CK tactic.
Anubis can exfiltrate files encrypted with the ransomware module from the device and can modify external storage. BusyGasper can collect images stored on the device and browser history. CHEMISTGAMES can collect files from the filesystem and account information from Google Chrome.
25 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Android malware that can take photos from both front and back cameras.
Mobile espionage spyware that obtains installed application lists.
Android spyware that exfiltrates arbitrary files, browsing history, SD card structure, and live-taken pictures.
Android trojan embedded into legitimate applications through Smali injection.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.