Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
12 distinct techniques documented for this family, organized by ATT&CK tactic.
“A second iteration adopted WebSocket communications for more resilient C2 channels.”
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Android dual-purpose ransomware and spyware distributed through sideloaded APKs. It requests extensive privileges, encrypts files on Android 9 and earlier, extorts victims through a Firebase chat interface, and collects and exfiltrates sensitive device, communications, account, location, screen-recording, camera, and gallery data. It also uses screen locks, overlays, app blocking, repeated pop-ups, and text-to-speech harassment to coerce victims.
Android malware combining ransomware and surveillance capabilities. It requests device-administrator, sensitive-data, and Accessibility permissions; encrypts files on Android 9 and earlier; deletes originals; displays ransom graphics; and supports extortion chat. It also collects device, account, communications, location, browser, notification, gallery, and credential data; captures screenshots and screen recordings; streams captures; takes silent photos; intercepts lock-screen PINs; and can lock or block applications and suppress touch input.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.