Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Researchers from Lab52 identified a malicious APK named “Process Manager” that acts as Android spyware, uploading information to the threat actors.
12 distinct techniques documented for this family, organized by ATT&CK tactic.
The Class o collects information from Wifis scanned by the device. For each of them it adds to the JSON its SSID and BSSID number.
The Class m adds information about the permissions a user has on each package to the JSON. It goes through the entire list of packages on the device and checks what permissions each package is requesting.
the application contacts the C2 (82.146.35[.]240) and identifies the device by its model, version, id and manufacturer.
We continue with the Class g that collects all the files in the device, saving in the JSON the name and the buffer of each one of them. In case a file cannot be accessed it also indicates it with “Access Denied”. In addition, it also lists the directories, indicating the name and path.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Android spyware APK that gains device admin privileges, hides its icon, runs in the background, collects extensive device data, and exfiltrates it to a C2 server. Capabilities described include harvesting installed packages, call logs, contacts, files, GPS location, clipboard contents, audio recordings, app permissions, SMS conversations, Wi‑Fi data, and notification contents; it can also send SMS and abuses referral installation of the Rozdhan app for profit.
Android spyware disguised as a system component that requests extensive permissions, hides its icon after installation, runs in the background, collects device data such as location, SMS, call logs, contacts, recordings, storage contents, and event notifications, and sends the stolen information in JSON format to a command-and-control server.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.