Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Malware

KYCShadow

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

MITRE ATT&CK

Techniques & procedures

10 distinct techniques documented for this family, organized by ATT&CK tactic.

Initial Access

1 technique
T1566.003Spearphishing via ServiceEvidence1

Distributed via WhatsApp, it tricks victims into installing what appears to be an official banking compliance application.

Stealth

3 techniques
T1036MasqueradingEvidence1

The application presents itself as a trusted banking KYC service, exploiting a routine process that millions of Indian bank users are already familiar with.

T1140Deobfuscate/Decode Files or InformationEvidence1

Once both approvals are given, the dropper begins decrypting an embedded payload using an XOR-based algorithm tied specifically to its own package name.

T1564Hide ArtifactsEvidence1

The payload also hides itself from the device app launcher, leaving no visible trace on the infected phone.

Credential Access

2 techniques
T1056Input CaptureEvidence1

Once installed, it guides users through convincing verification screens that collect mobile numbers, ATM PINs, Aadhaar numbers, and card details one step at a time.

T1649Steal or Forge Authentication CertificatesEvidence1

These allow the malware to intercept OTPs in real time, send and forward SMS messages remotely...

Collection

1 technique
T1056Input CaptureEvidence1

Once installed, it guides users through convincing verification screens that collect mobile numbers, ATM PINs, Aadhaar numbers, and card details one step at a time.

Command and Control

3 techniques
T1071Application Layer ProtocolEvidence1

It registers with Firebase Cloud Messaging, establishing a persistent push-based remote command channel for the attacker.

T1090ProxyEvidence1

Adding to the risk, the malware activates a full-tunnel VPN service that routes all device traffic through an attacker-controlled layer.

T1105Ingress Tool TransferEvidence1

The first application victims install acts as a loader that silently decrypts and deploys a secondary malicious payload in the background.

Exfiltration

1 technique
T1041Exfiltration Over C2 ChannelEvidence1

After users complete the flow, a fake confirmation message claims that “verification is in progress,” while all submitted data is already being transmitted to a remote attacker-controlled server at jsonapi[.]biz.

INDICATORS OF COMPROMISE

IOCs tracked for this family

4 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.

View more in app
Network
4 tracked

IPs, domains, and DNS infrastructure linked to this family.

TypeValueLatest sighting
domain●●●●●●●●●●●●View more in app2 months ago
domain●●●●●●●●●●●●View more in app2 months ago
domain●●●●●●●●●●●●View more in app2 months ago
domain●●●●●●●●●●●●View more in app2 months ago
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching4

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping10

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.