SilkBean is an Android surveillance remote access trojan used in mobile espionage campaigns primarily targeting Uyghurs, with broader campaign activity also targeting Tibetans and diaspora communities. It belongs to an interconnected surveillance toolkit that includes DoubleAgent, CarbonSteal, and GoldenEagle. Infrastructure overlap has linked these campaigns to China-linked activity tracked as GREF/APT15.
SilkBean supports more than 70 commands from its command-and-control server and uses HTTPS for command-and-control communication. Its capabilities include accessing contacts, call logs, SMS messages, browser data, and files in external storage; recording the screen; and accessing the device camera. It can read, modify, and send messages, and delete contacts, call logs, applications, SMS messages, email, plugins, and externally stored files. These functions support extensive remote surveillance, personal-data exfiltration, and manipulation of compromised devices.
SilkBean has been embedded in trojanized applications, including Uyghur- and Arabic-focused keyboards, alphabet tools, plugins, and applications impersonating official Google products. The surrounding campaigns distributed malicious applications through phishing and third-party application channels rather than Google Play, using community-relevant functionality and trusted branding to attract targeted users.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The surveillance tool SilkBean with extensive remote access trojan (RAT) features.
8 distinct techniques documented for this family, organized by ATT&CK tactic.
The surveillance apps of these campaigns were likely distributed through a combination of targeted phishing and fake third-party app stores.
Anubis can exfiltrate files encrypted with the ransomware module from the device and can modify external storage. BusyGasper can collect images stored on the device and browser history. CHEMISTGAMES can collect files from the filesystem and account information from Google Chrome.
26 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Android surveillance malware distributed through tailored, trojanized applications targeting Uyghur and Tibetan communities. Supports more than 70 server commands, including message manipulation and screen recording.
Android surveillanceware used in larger China-linked mobile APT campaigns to gather and exfiltrate personal user data to attacker-operated command-and-control servers; many samples were trojanized legitimate apps.
SilkBean is an Android surveillanceware used by APT15 to monitor and collect information from targeted mobile devices, particularly in espionage campaigns.
Android surveillance malware with extensive RAT capabilities used for remote access and spying.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.