Joker is an Android trojan family active since at least 2017 that is primarily used for toll fraud and unauthorized premium-service subscriptions. It has repeatedly been embedded in functional, legitimate-looking applications distributed through Google Play, including wallpaper, messaging, utility, photography, and personalization apps. Joker commonly uses staged, dynamically loaded DEX, JAR, or APK payloads, encryption, obfuscation, packers, and conditional activation based on SIM country or mobile-network information to evade application review and analysis.
Once activated, Joker communicates with command-and-control infrastructure to obtain configuration, payloads, and jobs. It can collect SMS messages, contacts, device information, and notification-delivered verification codes. Variants automate premium WAP and carrier-billing flows in hidden WebViews, manipulate subscription webpages through JavaScript bridges, process authorization messages, and send premium SMS messages. Notification-listener functionality may be used both to obtain one-time codes and to suppress billing-related alerts. Joker has targeted users across selected European and Asian countries, among others; individual variants have been tailored to particular mobile operators. Public reporting does not conclusively attribute the family to a specific operator or state actor.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
18 distinct techniques documented for this family, organized by ATT&CK tactic.
It continues to find new tricks and tactics to stay undetected by doing small changes in its code or changing the payload download techniques.
we recently noticed a new Joker malware sample on Google Play Store, which utilizes Android packers like “Tencent’s Legu” and “ijiami” packers to evade detection
Users may be unaware of any compromise at first glance because the Joker malware sample is contained in a functioning app. The app promises wallpapers and delivers on that promise — the malware is an unfortunate add-on.
GolayEngine.lay() decrypts the 308KB payload via ChaCha20 -> GolayEngine.vcg() executes it
The malware only attacks targeted countries... the victim has to be using a SIM card from one of these countries in order to receive the second stage payload... most of the discovered apps have an additional check, which will make sure that the payload won’t execute when running within the US or Canada.
and android.permission.READ_PHONE_STATE to get the SIM mobile country code. Joker is known to only run on devices with a SIM card (and only for specific SIM country codes).
The malware only attacks targeted countries... the victim has to be using a SIM card from one of these countries in order to receive the second stage payload... most of the discovered apps have an additional check, which will make sure that the payload won’t execute when running within the US or Canada.
The commands are passed from the C&C. Some of the possible commands: ... get – Send a GET request ... post – Send a POST request
151 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
31 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Previously analyzed Android malware family known for abusing carrier billing; it is mentioned only as contextual comparison and is not attributed to this operation.
Android billing fraud trojan that subscribes victims to premium services and intercepts confirmation SMS or push notifications. This variant uses a Rust-compiled native library with ChaCha20-encrypted payloads and abuses notification listener access to read OTPs, confirm subscriptions, and suppress notifications.
The report also noted ... the reappearance of the Joker and FakeApp malware on Google Play.
...embedding such malware families as Joker, Harly, Coper, and Adfraud.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.