RCSAndroid, short for Remote Control System Android, is a sophisticated Android surveillance implant associated with Hacking Team and documented in targeted operations since at least 2012. It is best characterized as mobile spyware designed for covert collection of communications, credentials, device data, and sensor-derived intelligence from compromised handsets. Public reporting linked its use to attacks against Android users in Saudi Arabia, and later exposure of its source code increased concern that its capabilities could be repurposed beyond its original operator set.
RCSAndroid is a modular framework that combines delivery components, browser exploitation, an APK-based installer, low-level collection code, and command-and-control functionality. Reported infection vectors included SMS-based lures directing targets to exploit-hosting websites and a trojanized news application distributed through Google Play. The exploit-based delivery chain abused vulnerabilities in default Android browsers on older Android versions, specifically CVE-2012-2825 and CVE-2012-2871, enabling compromise of Android 4.0 through 4.3 devices.
Once installed, RCSAndroid supports broad surveillance and data-theft functions. Reported capabilities include recording audio through the microphone, capturing photos with front and rear cameras, collecting SMS, MMS, and Gmail messages, harvesting Wi-Fi and online account passwords, gathering contacts, monitoring clipboard contents, capturing screenshots, tracking device location, and extracting or decoding communications from multiple messaging applications. It has also been reported to intercept voice communications in real time by hooking Android media services, reflecting a high level of engineering maturity for mobile espionage malware.
The malware targets Android devices and aligns with intrusive post-compromise espionage activity rather than financially motivated commodity abuse. Its breadth of collection, stealth-oriented design, and persistence characteristics place it among the more capable historical Android spyware families. Removal may be difficult in some cases, with reporting indicating that full remediation could require reflashing device firmware.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The malicious sites, in turn, exploited known exploits, designated as CVE-2012-2825 and CVE-2012-2871, and are present in the default browsers found in Android versions from 4.0 to 4.3. | RCSAndroid has been actively used since 2012 and has been known to researchers since 2014, when research group Citizen Lab detailed a Hacking Team backdoor used against Android users in Saudi Arabia.
The malicious sites, in turn, exploited known exploits, designated as CVE-2012-2825 and CVE-2012-2871, and are present in the default browsers found in Android versions from 4.0 to 4.3. | RCSAndroid has been actively used since 2012 and has been known to researchers since 2014, when research group Citizen Lab detailed a Hacking Team backdoor used against Android users in Saudi Arabia.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
RCSAndroid has been actively used since 2012 and has been known to researchers since 2014, when research group Citizen Lab detailed a Hacking Team backdoor used against Android users in Saudi Arabia.
13 distinct techniques documented for this family, organized by ATT&CK tactic.
The malicious sites, in turn, exploited known exploits, designated as CVE-2012-2825 and CVE-2012-2871, and are present in the default browsers found in Android versions from 4.0 to 4.3.
Gooligan steals authentication tokens that can be used to access data from multiple Google applications. RCSAndroid can collect passwords for Wi-Fi networks and online accounts, including Skype, Facebook, Twitter, Google, WhatsApp, Mail, and LinkedIn. Monokle can retrieve the salt used when storing the user’s password, aiding an adversary in computing the user’s plaintext password/PIN from the stored password hash.
Anubis can exfiltrate files encrypted with the ransomware module from the device and can modify external storage. BusyGasper can collect images stored on the device and browser history. CHEMISTGAMES can collect files from the filesystem and account information from Google Chrome.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Android malware that can capture photos using front and back cameras.
Android spyware that steals Wi-Fi and online account passwords from multiple services.
Android spyware that collects SMS, MMS, and Gmail messages.
Android spyware that steals Wi-Fi passwords and credentials for multiple online services.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.