Pallas is an Android mobile remote access trojan associated with Dark Caracal. It has been used in campaigns targeting Lebanese victims and has been distributed through trojanized applications hosted on watering-hole websites, enabling installation outside official app stores. The malware supports broad surveillance and device-profiling functions, including collection and exfiltration of call logs, contacts, SMS messages including newly received messages, installed application lists, and device metadata such as device identifiers, operating system version, and hardware characteristics. Pallas also supports active espionage functions including microphone audio capture and taking photographs with both front and rear cameras. In addition to data theft, it can download and install attacker-specified applications and delete attacker-specified files on compromised devices. Pallas has also used phishing-style popups to harvest user credentials. Exfiltration and command-and-control traffic have been observed over HTTP. Overall, Pallas is a mobile surveillance implant focused on Android devices, combining credential theft, reconnaissance, collection, exfiltration, and follow-on payload delivery.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Dark Caracal distributes Pallas via trojanized applications hosted on watering hole websites. Pallas has the ability to download and install attacker-specified applications.
5 distinct techniques documented for this family, organized by ATT&CK tactic.
FinFisher captures and exfiltrates SMS messages. FrozenCell has read SMS messages for exfiltration. Pallas captures and exfiltrates all SMS messages... Rotexy can also send a list of all SMS messages on the device to the command and control server. RuMMS uploads incoming SMS messages to a remote command and control server. Stealth Mango uploads SMS messages. Windshift has included SMS message exfiltration...
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Pallas is described as a mobile remote access trojan previously used in Dark Caracal campaigns.
Android malware that can capture images using both front and rear cameras.
Android malware that uses phishing popups to steal user credentials.
Mobile spyware that retrieves a full list of installed applications.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.