Roaming Mantis continued to expand its MoqHao Android malware operation—also tracked as Wroba and XLoader—using smishing messages, fake courier-themed apps, and region-specific landing pages to steal device data, credentials, and support financially motivated fraud. Researchers reported that the campaign evolved its delivery and evasion methods with allowlist-based download pages in South Korea, Multidex obfuscation, SMS-spamming automation, and phishing redirects aimed at Japanese online banking and carrier-billing accounts.
The operation also added a DNS changer capability that targeted Wi-Fi routers commonly used in South Korea, allowing attackers to alter DNS settings and redirect users on affected networks to malicious pages. Infrastructure analysis identified 14 command-and-control servers, while telemetry showed nearly 1.5 million victim communications from 67 countries since late 2022, with the heaviest activity still concentrated in East Asia—especially Japan—even as infections and APK downloads were observed across Europe, Africa, the Middle East, Oceania, and the Americas.

Pull IOCs and campaign context straight into your stack.
23 events from the most recent confirmed update back to the earliest known activity.
On 2023-03-31, Deutsche Telekom Security reported that newer MoqHao samples could bypass text-based router CAPTCHAs by sending images to an OCR service, enabling brute-force logins and DNS hijacking on targeted routers. The report said the router-targeting activity was focused mainly on ipTIME and other Asia-linked models, especially in South Korea, and published related infrastructure indicators.
Team Cymru observed the most recent victim connections around 03 March 2023 for MoqHao C2 server 91.204.227.43. The server was linked to a campaign targeting users in India.
Team Cymru observed last victim connections around 26 February 2023 for MoqHao C2 server 91.204.227.51. The infrastructure was linked to a campaign targeting users in France.
A third MoqHao sample, 5ceb8950759a8d9d31389d1370d381d158c79fbe, was first uploaded on 25 February 2023 by a user in Japan. It was configured to receive C2 information for 91.204.227.43:29872 from a VKontakte profile.
A second MoqHao sample, 198b55d4e7c7c0ee4fc4cbe13859533e651b91f6, was first uploaded on 20 February 2023 by a user in Canada. It was configured to retrieve C2 information for 198.144.149.142:28866 from a VKontakte profile.
Team Cymru observed the most recent victim connections to MoqHao C2 server 91.204.227.31 around 29 January 2023. The server was linked to a campaign targeting users in Australia.
December 2022 landing-page statistics showed active APK downloads across multiple countries, with Japan, Austria, and France recording the highest counts. The counters had been reset at the beginning of December 2022.
A MoqHao sample with hash 37134b50f0c747fb238db633e7a782d9832ae84b was first uploaded on 24 October 2022 by a user in Canada. It was configured to obtain C2 information for 91.204.227.31:28877 from a VKontakte profile.
In September 2022, Kaspersky analyzed Wroba.o sample MD5 f9e43cc73f040438243183e1faf46581 and found a newly implemented DNS changer function. The feature targeted specific Wi-Fi routers mainly used in South Korea and retrieved next-stage data from a VK account.
On 2022-07-04, Sekoia first observed a Roaming Mantis smishing campaign targeting mobile users in France with package-delivery lures. The operation used geofencing and OS checks to deliver MoqHao to Android users, fake Apple login pages to iPhone users, and was later estimated to have caused about 70,000 Android compromises in France.
Team Cymru reported observing nearly 1.5 million victim communications to MoqHao C2 servers since late 2022. The telemetry showed activity spanning 67 countries.
Kaspersky investigated Roaming Mantis activity throughout 2022 and documented continued financially motivated use of Wroba.o/MoqHao/XLoader. The campaign targeted multiple regions beyond its earlier East Asia focus.
In 2021, Roaming Mantis added France and Germany as primary targets alongside Japan, Taiwan, and Korea, reflecting a push to expand smishing-based infections into Europe. Kaspersky said the activity was significant enough to prompt public alerts from German police and French media.
In February 2020, the actor changed a Japanese smishing lure to advertise free masks related to the coronavirus issue. Japan Cybercrime Control Center warned about the lure.
In 2019, the actor used Multidex in an APK file to hide a malicious loader module while filling other DEX files with junk code. Kaspersky described this as an obfuscation technique to hinder analysis.
In 2019, Kaspersky observed two newer malware families in the campaign: Wroba.j and Fakecop. Wroba.j included SMS-spamming automation and IMSI-based targeting of Japanese carriers.
In 2019, Roaming Mantis used malicious APK icons impersonating courier brands customized by country, including Sagawa Express in Japan, Yamato Transport and FedEx in Taiwan, CJ Logistics in South Korea, and Econt Express in Russia.
From mid-2019 until 2022, the attackers mainly used smishing instead of DNS hijacking to deliver malicious landing-page URLs in most regions. DNS hijacking remained especially relevant in South Korea.
On 2018-11-26, Trend Micro reported that XLoader and FakeSpy shared 126 malware-delivery domains and overlapping social-media-based C2 hiding techniques, suggesting the two Android malware families were operated by the same actor or affiliated operators. The researchers also noted possible ties to the Yanbian Gang and said the combined campaigns had produced 384,748 victims globally as of October, mostly in South Korea and Japan.
By May 2018, Roaming Mantis had expanded its landing pages and malicious APKs to support 27 languages, added fake Apple phishing pages for iOS users, and served Coinhive-based browser cryptomining to PC visitors. Kaspersky also observed dynamic per-download APK generation and a newer C2 retrieval method using Outlook email subjects over POP3.
In 2018, Roaming Mantis added SMiShing as a distribution method for Wroba.g alongside DNS hijacking. This marked a shift toward SMS-delivered malicious links and APKs.
Kaspersky first observed Roaming Mantis activity in 2018 targeting Japan, South Korea, and Taiwan. The campaign used Android malware later referred to as Wroba/MoqHao/XLoader.
Team Cymru identified 14 MoqHao command-and-control servers by analyzing malware samples and pivoting on VKontakte-hosted configuration, WinRM banners, and RDP certificate metadata. The infrastructure was tied to campaigns targeting every continent.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 295 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
10 references tracked. Mallory keeps watching after this page renders.
blog.sekoia.io
Open sourcebroadcom.com
Open sourcetelekom.com
Open sourceteam-cymru.com
Open sourcesecurelist.com
Open sourcesecurelist.com
Open sourceblog.trendmicro.com
Open sourceblog.trendmicro.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.