RambleOn is a multi-stage Android spyware family associated with North Korea-linked espionage activity and assessed as part of the broader RokRAT malware lineage. It has been used in targeted operations against individuals of intelligence interest, including journalists reporting on North Korean affairs in South Korea. Reporting links its tradecraft and victimology to activity associated with APT37, also known as ScarCruft, although direct attribution of individual incidents is not always definitive.
RambleOn typically begins with social engineering that persuades the target to install a malicious Android application masquerading as a legitimate messaging tool. In documented cases, the lure was delivered through direct messaging and presented as a secure chat application. The initial application acts as a loader while maintaining enough benign-looking functionality to reduce suspicion. It dynamically retrieves and loads additional code from cloud storage services, enabling staged deployment and flexible payload updates.
The malware supports extensive surveillance and data theft from infected Android devices. Documented collection capabilities include contacts, SMS and MMS messages, call logs, audio, location data, device information, installed application data, media, and files stored on the device. It also includes functionality to record audio, copy, download, upload, and encrypt files, and to send or intercept messages. Later stages add persistent background services and remote tasking through mobile push-notification infrastructure, including Firebase Cloud Messaging, allowing operators to trigger actions and sustain continuous exfiltration.
RambleOn uses a modular architecture with dynamic code loading and cloud-backed command-and-control workflows. Observed implementations rely on cloud storage providers for payload delivery and exfiltration, and use push-based mechanisms to activate services and execute operator commands. This design improves resilience, blends malicious traffic with legitimate services, and supports long-term covert monitoring of mobile targets.
The malware is best understood as an Android espionage platform focused on persistent surveillance, collection, and exfiltration rather than disruption or monetization. Its targeting, operational security choices, and overlap with ScarCruft tradecraft place it within the ecosystem of North Korean state-aligned mobile spyware used against civil society, journalists, defectors, and other persons relevant to DPRK intelligence priorities.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
In 2022, I identified an Android malware campaign I classified as RambleOn... This was a highly notable campaign from North Korean threat actors targeting journalists who were reporting on North Korean affairs.
The malicious APK file named as RambleOn on this report, contains unique characteristic of 1) using infrastructure of pCloud and Yandex, 2) usage of FCM service for C&C communication.
12 distinct techniques documented for this family, organized by ATT&CK tactic.
The primary modus operandi of threats targeting CSO’s in the dataset relate to either spearphishing links or attachments. Spearphishing attachments consisted of malware droppers or Remote Access Trojans (RATs).
On December 7 th 2022, a journalist received a message over WeChat messenger application asking to talk privately about a sensitive topic. The both parties discuss messaging over a secure application and the sender suggests talking over an application called “Fizzle messenger” and proceeds to send a copy of the APK to lure a journalist to install.
Located at “ch.seme.services.LogUService”, the class contains dynamic Dex class loading via module “dalvik.system.DexClassLoader”. The malicious app uses the “DexClassLoader” to dynamically load a Dex file from a cloud storage endpoint (either pCloud or Yandex) and execute.
The secondary payload registers the device with Google’s Firebase Cloud Messaging to provide C2 mechanisms.
The “LogUService” then uses the DexClassLoader to load the Dex file class “plugin” and execute method “LogState”. This method, contained within the first payload, proceeds to gather information about the device, exfiltrate all SMS, MMS, call logs, audio and media and then finally calls “sendToServer()” method to upload files back to the cloud storage service.
7 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An Android-focused malware/tool in ScarCruft’s arsenal, mentioned alongside RokRAT.
An Android adaptation of the RokRAT malware family mentioned as part of ScarCruft's actively maintained cross-platform tooling.
Android spyware identified by the author in 2022 and classified as RambleOn. It is described as North Korea-linked malware targeting journalists covering North Korean affairs, with advanced spying capabilities and an evolution from earlier Android malware associated with APT37.
Android spyware malware delivered via a trojanized messaging app ('Fizzle') that acts as a first-stage loader, downloads a Dex payload from pCloud or Yandex, exfiltrates contacts, SMS/MMS, call logs, audio, location, device data and files, then installs a second-stage APK ('com.data.WeCoin') that uses Firebase Cloud Messaging for command-and-control and continuous data theft.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.