INSOMNIA is an iOS surveillance malware family associated with mobile espionage activity. It is designed to profile compromised devices and collect a broad range of user and application data, including contacts, call history, SMS messages, iMessages, installed non-Apple applications, device identifiers, storage information, and application database content such as data from Gmail, Hangouts, photos, and third-party app containers. Its behavior indicates a strong emphasis on intelligence collection from local device storage and communications artifacts.
The malware communicates with command-and-control infrastructure over HTTPS, allowing it to blend with normal encrypted application traffic while supporting remote tasking and data exfiltration. Reported collection of call history and certain protected local data on iOS suggests operation in a post-compromise context where elevated privileges may be available or where the implant otherwise has access beyond standard app sandbox restrictions. INSOMNIA fits the profile of mobile spyware used for persistent surveillance and theft of sensitive personal and application data from Apple mobile devices.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
INSOMNIA communicates with the C2 server using HTTPS requests.
"...contained malicious javascript code that resembled previously reported exploits, which installed iOS malware known as INSOMNIA on people’s devices once they were compromised."
8 distinct techniques documented for this family, organized by ATT&CK tactic.
“Compromising and impersonating news websites… compromised legitimate websites frequently visited by their targets as part of watering hole attacks… Some of these web pages contained malicious javascript code… which installed iOS malware known as INSOMNIA…”
“Social engineering: This group used fake accounts on Facebook to create fictitious personas posing as journalists, students, human rights advocates or members of the Uyghur community to build trust with people they targeted and trick them into clicking on malicious links.”
AbstractEmu can collect device IP address and SIM information; Android/SpyAgent has collected device network information, such as the IMEI and the phone number; ANDROIDOS_ANSERVER.A gathers the device IMEI and IMSI; many listed mobile malware families collect IMEI, IMSI, ICCID, MEID, serial number, phone number, MAC address, IP address, carrier, MCC/MNC, and related device/network identifiers.
Anubis can exfiltrate files encrypted with the ransomware module from the device and can modify external storage. BusyGasper can collect images stored on the device and browser history. CHEMISTGAMES can collect files from the filesystem and account information from Google Chrome.
21 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
24 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named ransomware involved in a healthcare-sector breach claim.
iOS implant capable of enumerating installed non-Apple applications.
Mobile spyware that retrieves SMS messages and iMessages.
Android spyware that collects app databases, photos, and third-party app container data.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.