Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
13 distinct techniques documented for this family, organized by ATT&CK tactic.
[The malware can] read SMS and one-time passwords, access call logs, contacts, browsing history, app lists, Google account information, and location.
The malware can steal lock-screen PINs to maintain persistent access... Overlays that steal lock-screen PINs.
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
Other indicator types observed in public reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Android malware distributed through phishing/social-engineering lures and malicious APKs outside Google Play. It abuses Accessibility permissions for device control; retrieves C2 details from GitHub; and can receive commands through Firebase or WebSockets. Its ransomware module encrypts selected shared-storage files on Android 9 and earlier using a victim-specific AES key, deletes originals, appends .enc, displays ransom notes, and provides a Firebase-hosted chat for ransom negotiation. It also steals lock-screen PINs, SMS/OTPs, call logs, contacts, browser and application data, Google-account information, location, WhatsApp and Telegram data; records screens and video, takes screenshots and camera photos, and includes intimidation/harassment capabilities.
Android hybrid ransomware and spyware targeting Indonesian victims. It requests device-administrator and Accessibility privileges; steals PINs, SMS/OTPs, contacts, calls, browser history, files, messaging data, location, screenshots, screen recordings, and camera images. It encrypts accessible files using an AES key obtained from its C2, appends .enc, and replaces images with ransom notices. Its second version adds WebSocket C2, app blocking, touch-blocking overlays, dialog/video/jumpscare harassment, and remote text-to-speech.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.