Mamont is an Android banking Trojan family that emerged in late 2023 and became one of the most prevalent mobile banking malware families affecting users in Russia, the CIS, and other regional campaigns through 2024–2026. It is actively developed, with numerous variants and both banker and dropper-classified samples observed in the wild. Mamont has been associated with large-scale Android banking Trojan activity and has repeatedly dominated mobile banker detections in industry telemetry.
Mamont is distributed through social-engineering lures rather than exploit-driven infection. Documented delivery schemes include fake parcel-tracking applications tied to fraudulent online storefronts and Telegram-based order scams, instant-message lures, fake offers in neighborhood or community chats, and trojanized Android applications such as a fake dating app targeting Uzbek-speaking users. Some variants use a multi-stage infection chain in which an initial Android dropper decrypts and installs a second-stage payload, including encrypted embedded APKs.
Once installed, Mamont requests extensive Android permissions related to SMS, phone state, calls, notifications, and background execution. Its core behavior centers on theft and abuse of financial communications. Observed capabilities include intercepting SMS messages, harvesting one-time codes, hijacking push notifications, collecting device and SIM information, enumerating installed applications, and extracting financial data from banking alerts. Certain variants parse multilingual SMS content for transaction and balance information. Mamont also supports remote command execution through command-and-control infrastructure, enabling operators to send SMS messages, place calls, issue USSD requests, retrieve recent messages, and trigger additional data collection.
Mamont also includes defense-evasion and post-compromise tradecraft. Operators can hide or alter the app icon, keep malicious logic running in the background, and use staged installation flows to transfer execution from a visible lure app to the real payload. Some variants expose custom prompts and image-upload interfaces that allow attackers to solicit additional victim data and support follow-on social-engineering fraud. These functions expand Mamont beyond simple OTP theft into broader account takeover and financial fraud operations.
Victimology is strongest for Android users in Russia and neighboring CIS markets, but localized campaigns have also targeted Uzbek-speaking users. Small businesses and individual consumers have both been targeted, especially where mobile devices are used for banking, order management, or receipt of transaction confirmations. Available reporting supports classifying Mamont as a mature, modular Android banking Trojan family focused on SMS and notification interception, remote fraud enablement, and socially engineered delivery.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
19 distinct techniques documented for this family, organized by ATT&CK tactic.
The app’s flow is designed to silently install this second APK and immediately launch its MainActivity.
the command and control (C2) server, whose address (http://84.21.189.36:2288) is stored base64encoded within the code
The attackers would then send what appeared to be the photo itself but was actually a malware installer... In reality, this was malware with no parcel-tracking functionality whatsoever.
Once installed, the primary app extracts an embedded file named data.bin from res/raw/ and decrypts it into a second APK.
When the app receives that command, the user sees a window with a text box for entering data, which is then sent to the command-and-control server.
The malware gathers sensitive device information, including installed apps, phone numbers, and operator/SIM details
It then asks the victim to enter the tracking number previously received from the scammers, and sends a POST request containing device information along with the number to the C2 server... The other one sets up a connection with the attackers’ WebSocket server.
9 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
16 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Android banking Trojan family that dominated real-world attack metrics in Q2 2026; newer variants rose sharply, and some packed banking samples were reclassified as droppers.
Active Android banking trojan family with multiple new variants dominating real-world attacks on users; some samples are also classified as droppers, indicating packaging and delivery changes.
Android banking malware family with multiple active variants dominating victim telemetry; newer variants rose sharply, and some packed samples were reclassified as droppers, indicating ongoing development and tactic shifts.
An Android malware variant discussed in the context of advanced dropper logic and an encrypted payload.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.