TangleBot is an Android malware family identified in 2021 that targeted mobile users in the United States and Canada through SMS-based social engineering. The campaign used lures themed around COVID-19 notifications and power outages, directing victims to Android-specific landing pages that presented a fake Adobe Flash Player update and persuaded users to sideload a malicious application package from unknown sources. TangleBot has been described as distinct from earlier Medusa-related mobile campaigns despite some similarities in theme and tradecraft.
Once installed, TangleBot requests extensive Android permissions that enable broad surveillance, device manipulation, and data theft. Documented capabilities include reading and sending SMS messages, accessing call logs, viewing contacts, accessing files and media, keylogging, screen capture, camera and microphone capture, clipboard access, GPS-based location tracking, and monitoring running applications and current windows. It also supports HTML overlay injection to present fraudulent application screens, including banking-style login prompts, for credential harvesting. The malware can place phone calls from the infected device, creating opportunities for impersonation and potential abuse of voice-based authentication workflows.
TangleBot supports a large command set for remote interaction with compromised devices and uses covert command-and-control discovery via social media messaging, including retrieval of instructions from Telegram posts. Reported samples also used obfuscation and anti-analysis measures such as hidden secondary code modules, minified code, excessive unused code, modular design, and encrypted or decrypted-at-runtime strings. Audio captured from the device microphone has been reported as transmitted using RTSP.
The malware is best characterized as a mobile surveillance and credential-theft platform with strong remote-control features. Its observed infection chain relied on smishing and fake-update social engineering rather than exploitation of a software vulnerability. High-confidence targeting observed in public reporting focused on Android users in North America.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
18 distinct techniques documented for this family, organized by ATT&CK tactic.
The control afforded by the malware allows for the monitoring and recording of all aspects of user activity, including websites visited, collection of typed passwords | HTML injection is used to generate fake application overlay screens. These screens may perfectly resemble the login pages of financial institutions and are designed to compromise the credentials of unsuspecting users.
The control afforded by the malware allows for the monitoring and recording of all aspects of user activity ... and can harvest data including SMS activity and stored content.
The control afforded by the malware allows for the monitoring and recording of all aspects of user activity, including websites visited, collection of typed passwords | HTML injection is used to generate fake application overlay screens. These screens may perfectly resemble the login pages of financial institutions and are designed to compromise the credentials of unsuspecting users.
The following is a short list of a few available C2 commands: ... Keylogging capability ... collection of typed passwords
The following is a short list of a few available C2 commands: ... Screen capture
The threat actor uses social media messaging to deliver covert C2 infrastructure information to infected devices. The messaging in the detected sample arrives via Telegram.
Figure 15. Telegram page showing C2 information and network GET request
4 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An Android malware-as-a-service operation discovered in 2020, mentioned only to distinguish it from Medusa ransomware.
Android malware delivered via SMS lures themed around COVID-19 and electricity outages. It tricks users into sideloading a fake Flash Player APK, requests extensive permissions, uses Telegram-based covert C2 discovery, supports keylogging, HTML overlay injection, SMS and call control, screen and camera capture, microphone recording, GPS tracking, clipboard access, and broad surveillance/exfiltration of victim data.
Android malware that requests permissions to access files and media on the device.
Android malware that requests permissions to access files and media on the device.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.