Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
13 distinct techniques documented for this family, organized by ATT&CK tactic.
Dutch authorities have shut down what is believed to be one of the largest botnet operations ever uncovered... approximately 200 servers located in the Netherlands were seized as part of the operation. These servers allegedly formed the backbone of a sophisticated botnet infrastructure...
The AppProWorker and the AppProReceiver classes are simply responsible for starting the service. The former starts the service when the application runs for the first time, and the latter enables the service’s persistence and executes whenever the device is booted.
The AppProWorker and the AppProReceiver classes are simply responsible for starting the service. The former starts the service when the application runs for the first time, and the latter enables the service’s persistence and executes whenever the device is booted.
были изъяты более 200 серверов, которые использовались для управления сетью из 17 млн зараженных устройств
The LumiApps platform promotes itself and its SDK as an alternative app monetization method to rendering ads to users. According to their FAQ and available information, the platform rewards developers with cash payment based on the amount of traffic that gets routed through user devices.
10 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A botnet that infected nearly 190,000 devices and integrated them into the Asocks residential proxy network.
Proxy botnet linked by researchers to Asocks infrastructure; it involved dozens of Android applications via a malicious SDK and turned infected devices into residential proxy nodes without users' knowledge.
A botnet/proxy malware operation linked to ASOCKS that enrolls infected devices into a residential proxy network, allowing their traffic to be routed through compromised systems without users’ knowledge.
A botnet/proxy malware operation linked to ASOCKS that covertly enrolls infected devices into a residential proxy network, allowing traffic routing through compromised consumer devices without user consent.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.