logo

Android spyware 'Mandrake' hidden in apps on Google Play since 2022

ID: fbe832f8-419e-59f8-96d7-9259fd1a3bbf

STIX ID: report--fbe832f8-419e-59f8-96d7-9259fd1a3bbf

Feed Name: Bleeping Computer

Threat Score
72/100

Date Published: 2024-07-29

Date Updated: 2026-07-17

Author: Bill Toulas

...
...

A new, heavily obfuscated variant of the Android spyware 'Mandrake' was found embedded in five Google Play apps (notably AirFS) downloaded ~32,000 times across multiple countries; the malware uses native libraries (libopencv_dnn.so and libopencv_java3.so), multi-stage in-memory DEX loading, OLLVM obfuscation, certificate-based C2, and a broad spying feature set (data collection, screen recording, remote command execution, UI simulation, and prompting installs). Kaspersky documented the apps, removal from the Play Store by March 2024, and recommended defenses (install from reputable publishers, check permissions/comments, keep Play Protect enabled) while warning the threat could return via new droppers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.