DEFENSOR ID is an Android malware family observed using mobile-specific persistence and command-and-control mechanisms. It abuses Android accessibility-related event handling to automatically start on device boot, providing persistence without requiring overt user interaction after installation. It has also been observed using Firebase Cloud Messaging as a command-and-control channel, allowing its operator communications to blend with legitimate mobile push-notification traffic. In post-compromise activity, DEFENSOR ID can enumerate installed applications on the device, a capability commonly used to profile victims, identify targeted apps, or assess the presence of security software. The malware targets Android devices and exhibits behavior associated with persistence, discovery, and command-and-control operations on mobile platforms.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct techniques documented for this family, organized by ATT&CK tactic.
DEFENSOR ID has used Firebase Cloud Messaging for C2; Rotexy can also communicate by using JSON messages sent through Google Cloud Messaging; Skygofree can be controlled via HTTP, XMPP, FirebaseCloudMessaging, or GoogleCloudMessaging in older versions.
AbstractEmu can use HTTP to communicate with the C2 server; AhRat can communicate with the C2 using HTTPS requests; Android/AdDisplay.Ashas has communicated with the C2 server using HTTP; Android/Chuli.A used HTTP uploads to a URL as a command and control mechanism; Asacub has communicated with the C2 using HTTP POST requests; BOULDSPY uses unencrypted HTTP traffic between the victim and C2 infrastructure; BRATA can use both HTTP and WebSockets to communicate with the C2 server; Bread communicates with the C2 server using HTTP requests; PROMETHIUM used StrongPity to communicate with the C2 server using HTTPS; Cerberus communicates with the C2 server using HTTP; Chameleon can use HTTP to communicate with the C2 server; CHEMISTGAMES has used HTTPS for C2 communication; Concipit1248 communicates with the C2 server using HTTP requests; Corona Updates communicates with the C2 server using HTTP requests; Dark Caracal controls implants using standard HTTP communication; EventBot communicates with the C2 using HTTP requests; Exobot has used HTTPS for C2 communication; Exodus One checks in with the command and control server using HTTP POST requests; FluBot can use HTTP POST requests on port 80 for communicating with its C2 server; FlyTrap can use HTTP to communicate with the C2 server; Golden Cup has communicated with the C2 using MQTT and HTTP; GoldenEagle has used HTTP POST requests for C2; GPlayed has communicated with the C2 using HTTP requests or WebSockets as a backup; Gustuff communicates with the command and control server using HTTP requests; Hornbill can use HTTP and HTTP POST to communicate information to the C2; INSOMNIA communicates with the C2 server using HTTPS requests; LightSpy has used both HTTPS and Websockets to communicate with the C2; Red Alert 2.0 has communicated with the C2 using HTTP; RedDrop uses HTTP requests for C2 communication; Riltok communicates with the command and control server using HTTP requests; Rotexy can communicate with the command and control server using JSON payloads sent in HTTP POST request bodies; RuMMS uses HTTP for command and control; SharkBot can use HTTP to send C2 messages to infected devices; SilkBean has used HTTPS for C2 communication; Skygofree can be controlled via HTTP; SpyC23 can communicate with the Command and Control server using HTTPS; TrickMo communicates with the C2 by sending JSON objects over unencrypted HTTP requests; ViceLeaker uses HTTP requests for C2 communication; YiSpecter has connected to the C2 server via HTTP.
DEFENSOR ID has used Firebase Cloud Messaging for C2. Rotexy can also communicate by using JSON messages sent through Google Cloud Messaging. Skygofree can be controlled via HTTP, XMPP, FirebaseCloudMessaging, or GoogleCloudMessaging in older versions. SpyC23 can communicate with the Command and Control server using HTTPS and Firebase Cloud Messaging (FCM). Trojan-SMS.AndroidOS.Agent.ao uses Google Cloud Messaging (GCM) for command and control. Trojan-SMS.AndroidOS.FakeInst.a uses Google Cloud Messaging (GCM) for command and control. Trojan-SMS.AndroidOS.OpFake.a uses Google Cloud Messaging (GCM) for command and control.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Android malware that retrieves the list of installed applications.
Mobile malware referenced as using Firebase Cloud Messaging for command and control.
Android malware that abuses accessibility services and related intents to auto-start on boot.
Android spyware that abuses accessibility service intents to auto-start on device boot for persistence.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.