Threat actors used COVID-19-themed lures to push Android malware through SMS phishing and unofficial download sites, targeting users with fake alerts, safety tools, and public-health claims. Proofpoint reported that the TangleBot campaign sent text messages in the United States and Canada themed around coronavirus information and power outages, directing Android users to links that served a malicious APK and a fake Adobe Flash Player update prompt. Separately, researchers documented a fake "Corona Safety Mask" app and similar coronavirus-themed Android packages that were distributed outside official app stores and promoted through deceptive websites and messages.
Once installed, the malware gave operators extensive access to infected devices. TangleBot supported surveillance and device control features including keylogging, SMS and call control, screen capture, camera and microphone access, GPS tracking, clipboard access, and overlay injection, while using obfuscation and Telegram-based command-and-control discovery to hinder analysis. The other Android trojan focused on propagation by requesting permission to read contacts and send SMS messages, harvesting address books and sending malicious texts with download links to additional victims; researchers also warned the app appeared capable of evolving toward broader fraud or theft functions.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
Proofpoint first detected the TangleBot mobile malware campaign in early September 2021. The campaign targeted Android users in the United States and Canada with SMS lures themed around COVID-19 notifications and power outages.
Proofpoint published technical analysis of TangleBot, describing its fake Flash update installation flow, Telegram-based command-and-control discovery, extensive surveillance and device-control features, and obfuscation methods. Proofpoint also said it worked with Google so Google Play Protect would detect the malware and released EmergingThreats detection rules for related activity.
Researchers described an Android malware campaign that used coronavirus-themed lures, including the fake "Corona Safety Mask" app and other bogus COVID-19 apps, to trick users into sideloading malicious APKs from unofficial domains. The malware harvested contacts and sent malicious SMS messages with download links to propagate further.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.