MoqHao, also known as Wroba, Shaoye, and XLoader for Android, is an Android malware family closely associated with the Roaming Mantis cybercrime operation. It has been active for years in large-scale mobile campaigns that initially concentrated on East Asia, especially Japan and Korea, and later expanded across Europe, Africa, the Middle East, Oceania, and the Americas. The malware is primarily distributed through smishing campaigns that impersonate parcel-delivery or service notifications and lure victims into installing malicious Android applications, often disguised as browser or app updates.
MoqHao is best characterized as an Android remote access trojan with information-stealing and backdoor functionality, and some reporting also describes variants as banking trojans or mobile spyware. Once installed, it commonly requests SMS-related permissions, can read and send text messages, collect device and user information, and communicate with attacker-controlled infrastructure for tasking. Observed campaigns have used social-media profiles as dead-drop resolvers to publish encrypted command-and-control configuration, demonstrating an emphasis on resilience and operational flexibility. Technical analyses have also documented packed and dynamically loaded payloads, native-code-assisted loading, encrypted assets, hidden icons, and other anti-analysis or defense-evasion measures.
A notable operational feature of MoqHao is its ability to propagate through SMS messaging in a worm-like fashion by sending further lure messages from infected devices. Some variants have also been observed starting malicious activity automatically after installation, reducing the need for explicit user execution. Beyond handset compromise, newer samples have been reported attempting to identify vulnerable wireless routers, solve text-based CAPTCHA challenges through OCR services, brute-force administrative logins, and alter DNS settings to support downstream phishing or malware delivery.
Roaming Mantis has used MoqHao in financially motivated campaigns against mobile users worldwide. Delivery infrastructure has employed geofencing and device fingerprinting to selectively serve Android malware to Android users while redirecting iPhone users to credential-harvesting pages, indicating coordinated cross-platform fraud operations. Targeting has frequently used logistics and package-delivery themes, and campaigns have affected consumers at significant scale.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
This blog post is part of an ongoing series of analysis on MoqHao (also referred to as Wroba and XLoader), a malware family commonly associated with Roaming Mantis. MoqHao is generally used to target Android users, often via an initial attack vector of phishing SMS messages (smishing).
Ever received a text message alerting you to problems with the delivery of a package - even though you weren't waiting for one? Then you've already met Moqhao in person, also known as Shaoye or XLoader. Moqhao is something like the bestseller from the Roaming Mantis malware family, ready to build a backdoor into your smartphone's Android operating system.
28 distinct techniques documented for this family, organized by ATT&CK tactic.
it also uses phishing pages to steal user credentials... The landing page identified the user’s device platform to provide malicious APK files for Android or redirect to phishing pages for iOS.
Finally, the DNS changer generates a URL query with the rogue DNS IPs to compromise the DNS settings of the Wi-Fi router, depending on the model
Furthermore, an ELF file, libarmeaib-v7alibdf.so, was embedded in the APK file: it uses Java Native Interface (JNI) for the second stage payload, for decryption and also part of the loading feature.
Potential victims were redirected by DNS hijacking to a malicious web page that distributed a Trojanized application spoofed Facebook or Chrome that is then installed manually by users.
Throughout 2020 and 2021, the criminal group behind Roaming Mantis made use of various obfuscation techniques in the landing page script in order to evade detection.
A scam impersonating the Tokyo Public Prosecutors Office. ● A kind of fraud.
Then, the encrypted payload is XORed using the embedded XOR key. After the XOR operation, as with previous samples, the data is decompressed using zlib to extract the payload, a Dalvik Executable (DEX) file.
When trying to “PWNtcha” a vulnerable router, Moqhao first determines the IP address of the router to request its web-based administration pages. By accessing this default pages, Moqhao can determine the router’s model.
the DNS changer connects to the hardcoded vk.com account “id728588947” to get the next destination
If the target clicks on the link, an HTTP request is sent to the server... The malware then retrieves its C2 server by requesting one of the social network profiles stored in the payload.
The malware connects to an email inbox using hardcoded outlook.com credentials via POP3. It then obtains the email subject (in Chinese) and extracts the real C2 address using the string “abcd” as an anchor.
it is configured to receive C2 information ( 91.204.227.31 :28877) from a user profile on VKontakte.
In this sample, the decrypted payload is saved as datadataggk.onulfc.jb.utxdtt.bkfilesd and executed to infect the malicious main module on victim devices.
272 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Android remote access trojan used in smishing campaigns. It is delivered via malicious SMS links, masquerades as a browser update, requests SMS-related permissions, can intercept/read/send SMS, steal data from the device and apps, access contacts and messages, and retrieve its C2 from Imgur dead-drop profiles.
Android banking trojan family used in campaigns targeting Japanese users.
Banking trojan family used in campaigns targeting Japanese users; specific behaviors not described in the provided text.
MoqHao is a credential-stealing malware that targets both Apple IDs and Android devices, distributing malicious APKs and leveraging cross-platform tactics.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.