Tangelo is an iOS surveillanceware family associated with a targeted espionage campaign alongside the Android malware Stealth Mango. It is designed for covert collection of sensitive data from compromised iPhones and includes functionality to gather SMS messages, call logs, browser history, pictures, videos, cellular identifiers, and audio, including call recordings and recordings of the device’s surrounding environment. The malware’s behavior is consistent with mobile spyware used for intelligence collection rather than financially motivated crime.
Tangelo has been linked to operations targeting government officials, diplomats, military personnel, and activists, with a concentration of victims in Pakistan, Afghanistan, India, Iraq, and the United Arab Emirates, and additional collected data involving U.S., Australian, and German officials and military personnel. Reporting has assessed the broader campaign as likely operated by members of the Pakistani military. The operation sought information of intelligence value, including communications, travel details, identity documents, location-related data, and other sensitive personal or official material.
The paired campaign’s Android component was primarily delivered through phishing lures sent by fake Facebook personas, and some infections may also have involved physical access to devices. While the specific delivery mechanism for Tangelo on iOS is not established with high confidence, its capabilities indicate post-compromise surveillance and exfiltration focused on persistent monitoring of victim communications and locally stored media. Tangelo is best characterized as iOS spyware used in targeted mobile espionage.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct techniques documented for this family, organized by ATT&CK tactic.
AbstractEmu can collect device IP address and SIM information; Android/SpyAgent has collected device network information, such as the IMEI and the phone number; ANDROIDOS_ANSERVER.A gathers the device IMEI and IMSI; many listed mobile malware families collect IMEI, IMSI, ICCID, MEID, serial number, phone number, MAC address, IP address, carrier, MCC/MNC, and related device/network identifiers.
Anubis can exfiltrate files encrypted with the ransomware module from the device and can modify external storage. BusyGasper can collect images stored on the device and browser history. CHEMISTGAMES can collect files from the filesystem and account information from Google Chrome.
15 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Nation-state mobile surveillanceware mentioned as a comparison for similar behavior.
iOS surveillanceware family associated with the same campaign targeting government officials, diplomats, military personnel, and activists.
Android spyware that accesses browser history and media files.
Mobile spyware with functionality to gather SMS messages.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.