SilkBean is an Android surveillance malware family with extensive remote-access trojan functionality that has been associated with China-linked mobile espionage activity. It has been linked to campaigns attributed to GREF, also known as APT15, and has primarily targeted Uyghur individuals, with some reporting also indicating targeting of Tibetans and users in multiple countries outside China. SilkBean has commonly been embedded in trojanized Android applications, including Uyghur- and Arabic-focused keyboards, alphabets, plugins, and official-looking Google-themed apps, while preserving expected app functionality to reduce suspicion.
SilkBean is designed for covert collection and remote control on compromised Android devices. Documented capabilities include access to contacts, call logs, SMS messages, browser data, files stored on external storage, and device camera resources. It can also send SMS messages and delete a wide range of local data, including contacts, call logs, applications, SMS messages, email, plugins, and files on external storage, supporting both surveillance and defense-evasion objectives. Command-and-control communications have been observed over HTTPS, consistent with blending malicious traffic into normal mobile network activity.
Operationally, SilkBean fits a broader ecosystem of Android surveillance tooling used in long-running espionage campaigns focused on personal data collection and exfiltration from mobile devices. Distribution has been associated with targeted phishing and fake third-party app stores rather than official app marketplaces. Its combination of trojanized delivery, data theft, SMS abuse, remote surveillance, and on-device data deletion makes it a notable component of mobile espionage operations targeting politically sensitive communities.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The Lookout Threat Intelligence team has discovered four Android surveillanceware tools, which we named SilkBean, DoubleAgent, CarbonSteal, and GoldenEagle.
8 distinct techniques documented for this family, organized by ATT&CK tactic.
The surveillance apps of these campaigns were likely distributed through a combination of targeted phishing and fake third-party app stores.
Anubis can exfiltrate files encrypted with the ransomware module from the device and can modify external storage. BusyGasper can collect images stored on the device and browser history. CHEMISTGAMES can collect files from the filesystem and account information from Google Chrome.
24 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Android surveillanceware used in larger China-linked mobile APT campaigns to gather and exfiltrate personal user data to attacker-operated command-and-control servers; many samples were trojanized legitimate apps.
SilkBean is an Android surveillanceware used by APT15 to monitor and collect information from targeted mobile devices, particularly in espionage campaigns.
Android surveillance malware with extensive RAT capabilities used for remote access and spying.
Android trojan previously used by GREF and mentioned as part of overlapping targeting against Uyghurs and other Turkic minorities.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.