logo

Roaming Mantis Amplifies Smishing Campaign with OS-Specific Android Malware

ID: 1f504e02-0235-535e-b674-0f5b9a750c60

STIX ID: report--1f504e02-0235-535e-b674-0f5b9a750c60

Feed Name: McAfee Labs Blog

Threat Score
70/100

Date Published: 2021-05-05

Date Updated: 2026-04-28

Author: ZePeng Chen

...
...

McAfee Mobile Research reports that the Roaming Mantis smishing campaign has targeted Asian Android users (notably Japan) with phishing SMS that lead to OS-specific fake apps (fake Chrome for Android 9 and earlier, fake Google Play for Android 10+) which install SmsSpy and related malware to exfiltrate SMS messages and contacts; the report describes infection flow, C2/update mechanisms (including hidden C2 in online documents), supported remote commands, and provides extensive IoCs (C2 IPs, update links, phishing domains, and sample hashes).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.