Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
In this blog post, we describe Chrysaor, a newly discovered family of spyware that was used in a targeted attack on a small number of Android devices... Chrysaor is believed to be related to the Pegasus spyware that was first identified on iOS.
15 distinct techniques documented for this family, organized by ATT&CK tactic.
Repeated commands: use alarms to periodically repeat actions on the device to expose data, including gathering location data.
Upon installation, the app uses known framaroot exploits to escalate privileges and break Android’s application sandbox.
Data collectors are used in conjunction with repeated commands to collect user data including, SMS settings, SMS messages, Call logs, Browser History, Calendar, Contacts, Emails, and messages from selected messaging apps
Keylogging: record input events by hooking IPCThreadState::Transact from /system/lib/libbinder.so
Screenshots: captures an image of the current screen via the raw frame buffer.
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Android spyware from NSO with capabilities similar to Pegasus. It used known rooting-style techniques rather than zero-day exploits, and if rooting failed it requested user permissions to collect partial data.
Targeted Android spyware used against a small number of victims. After installation it can escalate privileges, persist across factory resets, disable updates, collect extensive device and app data, capture screenshots, keylog, track location, exfiltrate communications data, and covertly activate microphone surveillance via 'RoomTap'. It also supports remote commands and self-removal.
Referenced as an example of malware using MQTT for C2 communications; no additional technical details provided in this content.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.