Threat actors distributed Android malware disguised as high-profile mobile games, using fake Super Mario Run and Pokémon GO APKs to lure users into sideloading infected apps. In both cases, the packages carried the DroidJack remote access trojan, also known as SandroRAT, allowing attackers to gain extensive control over compromised devices while presenting interfaces that mimicked the legitimate games and exploited demand around their releases.
Once installed, the malware registered infected devices and harvested sensitive data including SMS messages, call logs, call recordings, photos, videos, and WhatsApp content, storing stolen information locally before exfiltrating it to hardcoded command-and-control infrastructure. Proofpoint reported a Pokémon GO-themed sample configured to contact pokemon.no-ip.org over TCP and UDP port 1337, while Zscaler described a Super Mario Run lure that similarly used a hardcoded C2 server, underscoring the risk that third-party Android app downloads can expose both personal and enterprise-connected devices to full-device compromise.

Pull IOCs and campaign context straight into your stack.
5 events from the most recent confirmed update back to the earliest known activity.
A malicious Pokémon GO Android APK containing the DroidJack RAT was uploaded to a malicious file repository at 09:19:27 UTC. Proofpoint said the upload occurred less than 72 hours after the game's initial launch in Australia and New Zealand.
Pokémon GO was released in the United States two days after its initial Australia and New Zealand launch.
Pokémon GO was first released in Australia and New Zealand, creating immediate demand for unofficial Android APKs in regions where the game was not yet available.
A malicious Android package posing as Super Mario Run was found to install the DroidJack RAT instead of any legitimate game payload. Once installed, it registered infected devices and harvested data including calls, SMS logs, call logs, videos, photos, and WhatsApp information for exfiltration to a hardcoded command-and-control server.
Proofpoint researchers discovered an Android Pokémon GO APK backdoored with DroidJack, also known as SandroRAT. The sample mimicked the legitimate game's startup screen and was configured to contact pokemon.no-ip.org over TCP and UDP port 1337.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.