TangleBot is an Android mobile malware family identified in 2021 that targeted users in the United States and Canada through SMS-based social engineering. The campaign used themed lures related to COVID-19 notifications and power outages, directing victims to malicious links that served Android-specific content and prompted installation of a fake Adobe Flash Player update. Installation required users to approve sideloading and grant extensive permissions, enabling broad surveillance and device-control functions.
TangleBot supports a wide range of post-compromise capabilities. Reported functions include reading and sending SMS messages, accessing contacts, viewing call logs, accessing files and media, keylogging, screen capture, camera and microphone capture, clipboard collection, tracking running applications and current windows, GPS-based location tracking, and call placement. It also supports HTML overlay injection to impersonate legitimate application interfaces, including financial login screens, for credential theft. Audio recording components allow operator-directed microphone capture, and the malware has been associated with covert command-and-control discovery via social media messaging services, including retrieval of instructions from Telegram. Obfuscation features include hidden secondary code modules, minified code, unused code, and encrypted or decrypted strings at runtime.
TangleBot has been noted to share some similarities with Medusa-related Android activity, but it has been distinguished by its broader functionality, transmission methods, and stronger obfuscation. Its behavior is consistent with a surveillance-oriented Android trojan or RAT focused on credential theft, message abuse, device monitoring, and data exfiltration from compromised mobile devices.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
18 distinct techniques documented for this family, organized by ATT&CK tactic.
The control afforded by the malware allows for the monitoring and recording of all aspects of user activity, including websites visited, collection of typed passwords | HTML injection is used to generate fake application overlay screens. These screens may perfectly resemble the login pages of financial institutions and are designed to compromise the credentials of unsuspecting users.
The control afforded by the malware allows for the monitoring and recording of all aspects of user activity ... and can harvest data including SMS activity and stored content.
The control afforded by the malware allows for the monitoring and recording of all aspects of user activity, including websites visited, collection of typed passwords | HTML injection is used to generate fake application overlay screens. These screens may perfectly resemble the login pages of financial institutions and are designed to compromise the credentials of unsuspecting users.
The following is a short list of a few available C2 commands: ... Keylogging capability ... collection of typed passwords
The following is a short list of a few available C2 commands: ... Screen capture
The threat actor uses social media messaging to deliver covert C2 infrastructure information to infected devices. The messaging in the detected sample arrives via Telegram.
Figure 15. Telegram page showing C2 information and network GET request
4 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Android malware delivered via SMS lures themed around COVID-19 and electricity outages. It tricks users into sideloading a fake Flash Player APK, requests extensive permissions, uses Telegram-based covert C2 discovery, supports keylogging, HTML overlay injection, SMS and call control, screen and camera capture, microphone recording, GPS tracking, clipboard access, and broad surveillance/exfiltration of victim data.
Android malware that requests permissions to access files and media on the device.
Android malware that requests permissions to access files and media on the device.
Android malware that requests permissions to access files and media on the device.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.