INSOMNIA is iOS spyware that collects extensive device, communications, and application data from compromised devices. It can retrieve contacts, call history, SMS messages, and iMessages; enumerate installed non-Apple applications; and collect device identifiers and configuration information, including the phone number, ICCID, IMEI, serial number, iOS version, storage capacity, and active network interface. INSOMNIA can also obtain locally stored application databases, including Gmail and Hangouts data, device photos, and container data associated with third-party applications. It communicates with command-and-control infrastructure over HTTPS.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
INSOMNIA communicates with the C2 server using HTTPS requests.
"...contained malicious javascript code that resembled previously reported exploits, which installed iOS malware known as INSOMNIA on people’s devices once they were compromised."
8 distinct techniques documented for this family, organized by ATT&CK tactic.
“Compromising and impersonating news websites… compromised legitimate websites frequently visited by their targets as part of watering hole attacks… Some of these web pages contained malicious javascript code… which installed iOS malware known as INSOMNIA…”
“Social engineering: This group used fake accounts on Facebook to create fictitious personas posing as journalists, students, human rights advocates or members of the Uyghur community to build trust with people they targeted and trick them into clicking on malicious links.”
AbstractEmu can collect device IP address and SIM information; Android/SpyAgent has collected device network information, such as the IMEI and the phone number; ANDROIDOS_ANSERVER.A gathers the device IMEI and IMSI; many listed mobile malware families collect IMEI, IMSI, ICCID, MEID, serial number, phone number, MAC address, IP address, carrier, MCC/MNC, and related device/network identifiers.
Anubis can exfiltrate files encrypted with the ransomware module from the device and can modify external storage. BusyGasper can collect images stored on the device and browser history. CHEMISTGAMES can collect files from the filesystem and account information from Google Chrome.
21 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
25 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Data-theft-only extortion operation that does not deploy file encryption, instead relying exclusively on the threat of publishing stolen data.
Named ransomware involved in a healthcare-sector breach claim.
Mobile spyware that retrieves SMS messages and iMessages.
iOS implant capable of enumerating installed non-Apple applications.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.