logo

Mandrake spyware sneaks onto Google Play again, flying under the radar for two years

ID: 03665ae1-e0a0-56eb-8522-560b829cab04

STIX ID: report--03665ae1-e0a0-56eb-8522-560b829cab04

Feed Name: Securelist by Kaspersky

Threat Score
78/100

Date Published: 2024-07-29

Date Updated: 2026-04-29

Author: Tatyana Shishkova, Igor Golovin

...
...

Kaspersky analyzed a resurgence of the Mandrake Android spyware on Google Play (2022–2024), finding five apps with >32,000 installs that used heavy native-library obfuscation (OLLVM), certificate-pinned C2, extensive sandbox/Frida/root checks, and multistage delivery (dropper → loader → core). The malware exfiltrates device and account data, can install additional APKs, and supports VNC-like remote webview control and screen recording; the report includes technical details, C2 protocol opcodes, IOCs (file hashes, domains, IPs), and attribution consistent with prior Mandrake activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.