HenBox is an Android spyware family used for targeted cyberespionage and surveillance, particularly against Uyghurs in Xinjiang and users of Xiaomi devices running MIUI. It was publicly identified in early 2018, with samples dating to late 2015. HenBox is associated with the China-linked espionage activity cluster PKPLUG and shares command-and-control infrastructure with several other espionage malware families, including PlugX, Poison Ivy, Zupdax, and 9002.
HenBox is distributed through third-party Android application stores and masquerades as legitimate VPN or Android system applications. It can install a legitimate decoy application alongside its malicious components to preserve the appearance of normal functionality. After execution, it hides its launcher icon and uses encryption, compression, and obfuscation to conceal components and configuration data.
Its surveillance capabilities include collecting personal and device information, accessing contacts, intercepting SMS messages, tracking location, accessing microphones and cameras, and stealing data from messaging, communication, and social media applications. It also collects outgoing telephone numbers beginning with China's country code and enumerates applications and running processes. HenBox registers broadcast receivers to trigger execution on events including device boot, SIM-state changes, application installation, and connectivity changes, supporting persistence and background operation. It additionally responds to Xiaomi smart-home alerts, reflecting its device-specific targeting.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
In early 2018, Unit 42 discovered a new Android malware family that we named ‘HenBox’... HenBox often masquerades as legitimate Android apps... Once installed, HenBox steals information from the device... It can also access the phone’s microphone and cameras.
11 distinct techniques documented for this family, organized by ATT&CK tactic.
The surveillance apps of these campaigns were likely distributed through a combination of targeted phishing and fake third-party app stores.
Anubis can exfiltrate files encrypted with the ransomware module from the device and can modify external storage. BusyGasper can collect images stored on the device and browser history. CHEMISTGAMES can collect files from the filesystem and account information from Google Chrome.
26 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
29 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Older Android surveillance tool linked to the mobile cluster through shared infrastructure and other technical overlaps. A server shared with CarbonSteal provides a reported connection to earlier desktop espionage activity, although FireEye subsequently revised the attribution of that older activity.
Android surveillance tool previously observed targeting Chinese-speaking individuals and members of the Uyghur ethnic minority; described as part of the same actor's mobile surveillance arsenal.
Android malware targeting Xiaomi MIUI devices, used by APT15.
Android malware in APT15's arsenal that targets Xiaomi devices running MIUI.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.