SimBad is an Android malware family embedded into otherwise legitimate applications as a trojanized component. It is associated with deceptive app repackaging and masquerading techniques to gain installation on victim devices. Once present, SimBad uses Android broadcast receivers for event-triggered execution, specifically registering for device boot and user-presence events so it can automatically perform actions after reboot and when the device is actively in use. This behavior supports persistence and ongoing background operation on infected devices. SimBad is also capable of installing attacker-specified applications, indicating use as a secondary-stage delivery mechanism for additional malicious payloads. The malware targets Android devices and is notable for combining trojanized-app distribution with persistent event-driven execution and follow-on app installation.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct techniques documented for this family, organized by ATT&CK tactic.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Rogue Android adware that uses broadcast intents to trigger actions after boot and during user activity.
Android adware embedded into legitimate applications.
Rogue adware campaign embedded into legitimate Android applications.
Rogue adware campaign capable of installing attacker-specified applications.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.