HenBox is an Android surveillance malware family associated with China-aligned espionage activity and linked to the broader PKPLUG intrusion set. It has been observed since at least 2015 and is primarily used for intelligence collection and victim tracking, with targeting focused on Uyghur individuals and other victims in and around Southeast Asia. Reporting has also tied it to campaigns affecting Xiaomi devices and devices running MIUI.
HenBox commonly masquerades as legitimate Android applications, including VPN software and Android system apps, and has been distributed through third-party Android app stores rather than the official Play ecosystem. It can also embed or install a legitimate decoy application to reduce user suspicion. After execution, it may hide its launcher icon and uses obfuscation and encrypted or compressed components to hinder analysis.
The malware supports persistent, event-driven execution through multiple Android broadcast receivers, allowing it to react to system and application events such as device boot, SIM-state changes, package installation, time changes, network connectivity changes, and Xiaomi-related smart-home alerts. HenBox is capable of broad device surveillance and data theft, including interception of SMS messages, collection of contact data, harvesting of selected call-related information, enumeration of running applications and processes, and theft of data from chat, communication, and social media applications. It also supports access to device sensors and peripherals used for surveillance, including the microphone and camera, and can track device location.
HenBox forms part of a wider mobile surveillance arsenal that has also included PluginPhantom, Spywaller, and DarthPusher. Infrastructure and tradecraft overlaps have linked it with Windows malware families and backdoors such as Farseer, PlugX, Poison Ivy, Zupdax, and the 9002 Trojan, reinforcing its role in a long-running cross-platform espionage ecosystem.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
In early 2018, Unit 42 discovered a new Android malware family that we named ‘HenBox’... HenBox often masquerades as legitimate Android apps... Once installed, HenBox steals information from the device... It can also access the phone’s microphone and cameras.
11 distinct techniques documented for this family, organized by ATT&CK tactic.
The surveillance apps of these campaigns were likely distributed through a combination of targeted phishing and fake third-party app stores.
Anubis can exfiltrate files encrypted with the ransomware module from the device and can modify external storage. BusyGasper can collect images stored on the device and browser history. CHEMISTGAMES can collect files from the filesystem and account information from Google Chrome.
26 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
26 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Android surveillance tool previously observed targeting Chinese-speaking individuals and members of the Uyghur ethnic minority; described as part of the same actor's mobile surveillance arsenal.
Android malware targeting Xiaomi MIUI devices, used by APT15.
Android malware referenced only as the context where Zupdax was first publicly mentioned due to shared infrastructure; no further HenBox analysis provided here.
Android malware that can access the device camera.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.