Researchers reported that the Roaming Mantis campaign hijacked DNS settings on compromised routers and redirected users to malicious landing pages that pushed Android malware. Victims who attempted to browse the web while connected to affected networks were instead shown fake update prompts, allowing the attackers to install malware on Android devices and potentially harvest credentials and other sensitive data.
The operation stood out because it abused home and small-office networking infrastructure rather than relying solely on phishing or malicious apps. By tampering with router DNS configurations, the attackers were able to intercept traffic at the network level and selectively deliver malicious content to mobile users, expanding the reach of the campaign and demonstrating how router compromise can be used to spread malware across connected devices.

See affected versions and whether adversaries are exploiting it.
1 event from the most recent confirmed update back to the earliest known activity.
Securelist published research describing the Roaming Mantis campaign using DNS hijacking to redirect users and infect Android smartphones. The report identified the campaign as an active mobile threat affecting users through compromised network infrastructure.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.