logo

MoqHao evolution: New variants start automatically right after installation

ID: 21b0a937-d648-510c-945a-9ceebd98fcfb

STIX ID: report--21b0a937-d648-510c-945a-9ceebd98fcfb

Feed Name: McAfee Labs Blog

Threat Score
80/100

Date Published: 2024-02-08

Date Updated: 2026-04-28

Author: McAfee Labs

...
...

> McAfee analysis of the MoqHao (Roaming Mantis) Android malware describes an active smishing campaign that installs apps which auto-execute without user launch, abuses Android install-time uniqueness checks and Unicode app names to evade detection, uses social engineering to set default SMS handling, retrieves phishing content from Pinterest, communicates with a WebSocket C2 offering extensive commands (exfiltrate SMS/contacts/photos, control device state), and includes multiple SHA256 and package-name IOCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.