PluginPhantom is an Android spyware family used in China-linked mobile espionage campaigns. It has been deployed by Earth Empusa, also known as Evil Eye, in operations targeting predominantly Uyghur activists, journalists, and dissidents living outside China, including in Turkey, Kazakhstan, the United States, Syria, Australia, and Canada. Distribution includes trojanized Uyghur-themed applications offered through websites impersonating third-party Android app stores. These applications include keyboards, prayer utilities, and dictionaries. Operators have used fake social-media personas posing as journalists, students, human-rights advocates, and community members to direct targets to malicious websites. PluginPhantom is also part of a broader Android surveillance arsenal that includes HenBox, Spywaller, and DarthPusher. Its role is mobile surveillance; specific collection functions are not sufficiently established to enumerate.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Older Android tools already in the same arsenal: HenBox, PluginPhantom, Spywaller, and DarthPusher.
"...trojanized ... applications... with two Android malware strains — ActionSpy or PluginPhantom."
"...trojanized ... applications... with two Android malware strains — ActionSpy or PluginPhantom."
4 distinct techniques documented for this family, organized by ATT&CK tactic.
The surveillance apps of these campaigns were likely distributed through a combination of targeted phishing and fake third-party app stores.
The surveillance apps of these campaigns were likely distributed through a combination of targeted phishing and fake third-party app stores.
“Social engineering: This group used fake accounts on Facebook to create fictitious personas posing as journalists, students, human rights advocates or members of the Uyghur community to build trust with people they targeted and trick them into clicking on malicious links.”
11 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Older Android malware tool identified as part of the same arsenal as the featured surveillance families. The article does not describe its individual capabilities.
Android surveillance tool previously observed targeting Chinese-speaking individuals and members of the Uyghur ethnic minority; described as part of the same actor's mobile surveillance arsenal.
Android-targeted malware family attributed in prior reporting to POISON CARP, referenced here for attribution context (links to Chinese development companies).
Android malware delivered through trojanized apps (e.g., keyboard/prayer/dictionary) hosted on attacker-controlled fake app stores; used for surveillance against targeted communities.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.