CarbonSteal is an Android spyware family used in China-linked mobile surveillance campaigns primarily targeting Uyghurs, with broader campaign targeting extending to Tibetans and diaspora communities. It belongs to an interconnected surveillance toolkit that includes SilkBean, DoubleAgent, and GoldenEagle. Shared infrastructure has linked this mobile activity to operations tracked as GREF/APT15.
CarbonSteal accesses SMS and MMS messages, records audio, and collects device and network metadata, including hardware characteristics, storage and memory information, serial numbers, cellular identifiers, and network statistics. It also searches for specific installed applications. Samples observed by 2019 abused Android accessibility services to extract chat messages. The implant accepts commands through specially crafted SMS messages and can exfiltrate collected information by SMS, supporting surveillance when mobile data connectivity is unavailable or unreliable.
CarbonSteal can silently answer calls from a preconfigured number, suppress the ringer, and expose ambient audio to the remote caller. It removes call-log entries associated with command-and-control sources to conceal this activity. Malicious applications impersonate trusted software, including official Google applications, messaging clients, VPN applications, and popular games. Its associated surveillance campaigns used trojanized applications distributed through third-party stores and community-oriented channels rather than Google Play.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Specially crafted text messages can task the implant. Collected data can go back out by SMS.
6 distinct techniques documented for this family, organized by ATT&CK tactic.
AbstractEmu can collect device IP address and SIM information; Android/SpyAgent has collected device network information, such as the IMEI and the phone number; ANDROIDOS_ANSERVER.A gathers the device IMEI and IMSI; many listed mobile malware families collect IMEI, IMSI, ICCID, MEID, serial number, phone number, MAC address, IP address, carrier, MCC/MNC, and related device/network identifiers.
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Android surveillance implant capable of SMS-based tasking and data exfiltration, enabling operation with poor or unavailable mobile data. Can record audio, silently answer calls from a configured number, suppress ringing, and remove the resulting call-log entry. Later samples abused accessibility services to extract chat messages.
Android surveillanceware used in larger China-linked mobile APT campaigns to gather and exfiltrate personal user data to attacker-operated command-and-control servers; many samples were trojanized legitimate apps.
CarbonSteal is an Android surveillanceware used by APT15 to collect sensitive information from mobile devices.
Trojan referenced as one of the malware families previously used by GREF in similar targeting.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.