Roaming Mantis is a financially motivated mobile-focused malware operation and associated Android malware cluster also tracked as MoqHao and XLoader. It has been linked to the Yanbian Gang and is known primarily for large-scale smishing campaigns that impersonate parcel-delivery or app-update notifications to trick users into installing malicious Android applications, often disguised as updates for popular services such as browsers or social-media apps. The operation initially concentrated on Asian victims and later expanded internationally with multilingual landing pages and broader regional targeting.
On Android, Roaming Mantis functions as a malware platform for credential and financial theft, device compromise, and further propagation. Reported capabilities include stealing sensitive information, installing additional applications, and abusing infected devices to send more SMS phishing messages. Some variants have been described as Android banking trojans. The malware has also used backdoor-style command handling and evolving command-and-control retrieval methods, including techniques intended to improve resilience and evade disruption.
A notable feature of the operation is its use of DNS hijacking to redirect victims from legitimate destinations to attacker-controlled landing pages. Beyond redirecting mobile users to malicious APK delivery sites, the campaign also expanded to iOS-focused phishing, presenting fake Apple-themed pages designed to harvest account and payment-card data from iPhone users. For desktop users, operators have also used browser-based cryptocurrency mining on malicious landing pages.
Roaming Mantis has additionally demonstrated router-compromise functionality through its MoqHao component. On infected Android devices, the malware can identify local router models, interact with web administration interfaces, bypass text-based CAPTCHA protections using OCR services, brute-force router logins, and alter DNS settings. This enables downstream DNS hijacking and redirection to phishing or malware-delivery infrastructure. Reporting has indicated particular focus on certain Asia-linked router brands and on victims in South Korea during observed router-targeting activity.
The campaign is notable for continuous operational adaptation, including multilingual lures, dynamic payload generation, randomized package naming, and changing infrastructure-discovery mechanisms. Its victimology has spanned multiple countries across Asia, Europe, the Middle East, and elsewhere, with observed emphasis varying over time. Overall, Roaming Mantis is best characterized as a mobile-centric criminal malware ecosystem combining smishing-based initial access, credential theft, banking-trojan behavior, propagation, and network-level redirection through compromised routers.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Over the years, the Yanbian Gang expanded their criminal operation to target countries all over the world with a collection of Android malware known as the Roaming Mantis.
“Roaming Mantis is a financially motivated actor… used SMS to distribute its malware to Android devices…”
49 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A collection of Android malware associated with the Yanbian Gang that includes fake apps impersonating banking services, cryptomining, multilingual phishing, and other fraudulent activity; Moqhao is described as part of this collection.
Android banking trojan campaign spread via DNS hijacking that redirects victims to malicious landing pages serving trojanized Facebook/Chrome APKs. It steals banking and other credentials, supports backdoor commands, retrieves C2 information from legitimate sites or later via Outlook POP3 email subjects, expanded to iOS credential phishing, and added browser-based crypto-mining for PC visitors.
Mobile malware ecosystem distributed via SMiShing; expanded to multiple languages, targets iOS and Android, and has included cryptocurrency mining and additional families in its arsenal.
Mentioned as an example of delivery logic using User-Agent checks, not part of the analyzed malware symphony.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.