MobileOrder is an Android spyware family associated with the Scarlet Mimic threat actor and used in a long-running surveillance campaign targeting the Uyghur community and related supporters since at least 2015. It has typically been distributed outside official app stores through social-engineering lures masquerading as Uyghur-themed documents, images, or audio content. After execution, the malware displays decoy content while operating covertly in the background.
MobileOrder is designed for persistent mobile surveillance and data theft. It collects device information, SMS messages, call logs, location data, files stored on the device, browser bookmarks, and information about running processes. It exfiltrates stolen data over the same channel used for command-and-control communications. The malware also supports extensive remote tasking, including executing shell commands, downloading files, taking screenshots, taking photos, recording ambient audio, recording phone calls, sending SMS messages, placing calls, and deleting SMS messages or call-log evidence.
The malware includes mechanisms to maintain access and resist removal, including hiding its icon, launching background services, using Android broadcast receivers to keep core services active, and in some variants requesting Device Admin or root privileges. It can also install or uninstall APKs, either silently when privileges permit or through standard Android user interface flows. Recent variants use native Android location APIs for real-time tracking and can buffer collected geolocation data locally for later upload when connectivity returns. Command-and-control communications have used encrypted exchanges and, depending on the variant, hardcoded infrastructure, dead-drop resolution, or both.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Since 2015, CPR has identified more than 20 samples of Android spyware called MobileOrder, with the latest variant dated mid-August 2022.
18 distinct techniques documented for this family, organized by ATT&CK tactic.
The malware can receive commands to execute a remote shell, which is done by starting a thread that, in turn, starts a shell process and establishes a socket connection to the same C&C server, but over a different port.
When the victim opens the lure, whether it is a document, picture, or audio file, it actually launches the malicious application, which in turn opens a decoy document to distract the victim from background malicious actions. | As there are no indications that any of them were distributed from the Google Store, we can assume the malware is distributed by other means, most likely by social engineering campaigns. In most cases, the malicious applications masquerade as PDF documents, photos, or audio.
A few of these changes were clearly developed to reduce the chances of the malware being detected by security solutions: the malware authors experimented with ways to hide the malicious strings..., first by moving them to the resources section, and later encoding them in base64.
To secure communication with the C&C server, the malware encrypts the data with AES. The key is generated in runtime from an encrypted passphrase inside dex by calculating the MD5 digest.
Tasklist can be used to discover processes running on a system. Numerous malware families and threat groups are described as listing running processes, collecting PIDs, checking for specific process names, or enumerating loaded modules.
The content repeatedly describes malware and threat actors collecting OS version, computer name, architecture, CPU, memory, disk, BIOS, language, and other host details; examples include use of commands such as ver, systeminfo, hostname, uname -m, and WMI to gather host information.
Andariel has collected large numbers of files from compromised network systems for later extraction... APT28 has retrieved internal documents from machines inside victim environments... BADNEWS crawls the victim's local drives and collects documents... many listed groups and malware collect files, documents, credentials, payment card data, or other information from compromised hosts.
The core service launches the Communication thread, which connects to the C&C (command & control) server and processes the commands received... The malware then creates a socket connection to the specified IP and port.
46 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Android spyware used in a long-running surveillance campaign targeting the Uyghur community. It masquerades as documents, photos, or audio files, steals device information, SMS, contacts, call logs, files, and location data, supports real-time tracking, records calls and ambient audio, can take photos and screenshots, send SMS, place calls, install APKs, and execute remote shell commands via C2.
Mobile malware that exfiltrates data collected from victim devices.
Malware that exfiltrates data to its C2 server using the same protocol as its C2 traffic.
Backdoor malware that uploads information about all running processes to C2.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.