SunBird is an Android surveillance malware family and remote access trojan associated with the Confucius threat actor, a pro-India espionage group known for targeting Pakistani and other South Asian entities. It has been used against individuals linked to Pakistan’s military and nuclear organizations as well as election-related targets in Kashmir, and victim data indicates broader targeting that also included apparent spouseware or stalkerware use cases.
SunBird is a comparatively full-featured mobile implant that combines surveillance collection with attacker-directed remote access. It can collect and exfiltrate contacts, call logs, phone number and IMEI data, device identifiers and profiling information such as model, manufacturer, and Android version, and images stored on external storage. Reported functionality also includes collection of installed application lists, browser history, calendar data, BBM and WhatsApp files, and IMO message content. SunBird stores harvested data locally in SQLite databases, compresses the collected information into ZIP archives, and periodically uploads the archives to command-and-control infrastructure.
Beyond bulk data theft, SunBird supports RAT-style tasking. It can execute commands on infected devices and, when conditions permit, run arbitrary commands with root privileges. It has also been reported to download operator-specified content from FTP shares. The malware’s behavior indicates a design optimized for sustained mobile surveillance and post-compromise operator control rather than simple one-time theft.
SunBird has been observed hosted on third-party Android app stores rather than official distribution channels, with no direct use of exploits reported in deployment. It is part of a broader Confucius mobile surveillance ecosystem that also includes Hornbill and earlier Android tooling such as ChatSpy. Assessments have linked SunBird to developers associated with another spyware family known as BuzzOut, suggesting overlap with commercial surveillanceware development practices.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
While SunBird features remote access trojan (RAT) functionality – a malware that can execute commands on an infected device as directed by an attacker – Hornbill is a discreet surveillance tool used to extract a selected set of data of interest to its operator.
13 distinct techniques documented for this family, organized by ATT&CK tactic.
AbstractEmu can collect files from or inspect the device’s filesystem. AhRat can find and exfiltrate files with certain extensions, such as .jpg, .mp4, .html, .docx, and .pdf. BOULDSPY can access browser history and bookmarks, and can list all files and folders on the device.
Examples in the content include: 'Riltok can access and upload the device's contact list to the command and control server,' 'Rotexy can access and upload the contacts list to the command and control server,' and multiple entries stating malware can 'exfiltrate' contacts.
23 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Android surveillanceware with RAT capabilities that continuously uploads stolen data to C2 servers. It exfiltrates call logs, contacts, device metadata, geolocation, images, installed apps, browser history, calendar data, BBM and WhatsApp files, and IMO content; it can also download attacker-specified content from FTP shares, scrape BBM/WhatsApp data via accessibility services, and run arbitrary commands as root if possible.
Android malware that accesses images on external storage.
Malware that accesses images on external storage.
Malware that accesses images on external storage.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.