Android/SpyAgent is an Android malware family documented as collecting device network information, including the IMEI and phone number, and exfiltrating SMS and MMS messages from compromised devices. Based on the provided content, its observed capabilities include harvesting subscriber/device-identifying information and stealing message content. The available context does not specify infection vector, associated threat actor, targeted industries, or additional indicators of compromise.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct technique documented for this family, organized by ATT&CK tactic.
AbstractEmu can collect device IP address and SIM information; Android/SpyAgent has collected device network information, such as the IMEI and the phone number; ANDROIDOS_ANSERVER.A gathers the device IMEI and IMSI; many listed mobile malware families collect IMEI, IMSI, ICCID, MEID, serial number, phone number, MAC address, IP address, carrier, MCC/MNC, and related device/network identifiers.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Android spyware that exfiltrates SMS and MMS messages.
Android spyware that exfiltrates SMS and MMS messages.
Android malware that collects device network information including IMEI and phone number.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.