DoubleAgent is an Android spyware family used in targeted surveillance campaigns against Tibetan and Uyghur communities. Its history extends to at least 2013, including an Android implant used against Tibetans. Later samples circulated through Uyghur-language third-party application stores. DoubleAgent has been embedded in trojanized versions of legitimate applications, including Voxer, TalkBox, and Amaq News, using familiar application functionality to conceal surveillance capabilities.
DoubleAgent collects SMS and MMS messages, contacts, call logs, files, basic system information, and lists of installed applications. It exfiltrates data using FTP and TCP sockets and can delete or rename specific files. These capabilities support device profiling and theft of personal communications and stored data.
The family forms part of a China-linked Android surveillance cluster that also includes SilkBean, CarbonSteal, and GoldenEagle, connected through shared infrastructure, signing certificates, and code overlap. DoubleAgent infrastructure has also overlapped with infrastructure used by BadBazaar.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Citizen Lab published a 2013 Android sample used against Tibetans that Lookout later placed in the DoubleAgent family.
6 distinct techniques documented for this family, organized by ATT&CK tactic.
The surveillance apps of these campaigns were likely distributed through a combination of targeted phishing and fake third-party app stores.
Anubis can exfiltrate files encrypted with the ransomware module from the device and can modify external storage. BusyGasper can collect images stored on the device and browser history. CHEMISTGAMES can collect files from the filesystem and account information from Google Chrome.
4 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
24 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Android surveillance family used against Tibetans and distributed through Uyghur-language third-party application channels. The article reports shared infrastructure with BadBazaar.
Android surveillanceware used in larger China-linked mobile APT campaigns to gather and exfiltrate personal user data to attacker-operated command-and-control servers; many samples were trojanized legitimate apps.
DoubleAgent is an Android surveillanceware used by APT15 for espionage and monitoring of targeted individuals.
Named malware referenced through overlapping C2 infrastructure with BADBAZAAR-linked domains.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.