Stealth Mango is an Android surveillanceware family associated with targeted mobile espionage. It has been linked to a campaign aimed at government officials, diplomats, military personnel, and activists, with victims concentrated in Pakistan, Afghanistan, India, Iraq, and the United Arab Emirates, and with collected data also affecting U.S., Australian, and German officials and military personnel. The operation has been assessed as likely connected to members of the Pakistani military.
Stealth Mango is designed for broad device monitoring and data theft. Observed capabilities include uploading call logs and SMS messages, collecting installed-package information, harvesting contact lists from third-party communication applications, recording audio through the device microphone, capturing images with the front and rear cameras, deleting incoming SMS messages from specified numbers or containing specified strings, and collecting changes to SIM-card or phone-number information. It also exfiltrates locally stored content from compromised devices, including documents, photos, and audio files.
The malware was primarily delivered through phishing lures sent by fake Facebook personas, with some infections possibly involving physical access to victim devices. No exploit use was required to obtain substantial intelligence from infected phones. The surveillance activity focused on information of intelligence value, including communications, travel details, identity documents, legal and medical records, geolocation-related data, and other sensitive personal or governmental material. Stealth Mango is part of a paired mobile surveillance operation alongside the iOS family Tangelo.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
7 distinct techniques documented for this family, organized by ATT&CK tactic.
The actors behind Stealth Mango typically lure victims via phishing messages sent by fake Facebook personas
but in some cases may have used physical access to victims' devices.
AbstractEmu can collect device IP address and SIM information; Android/SpyAgent has collected device network information, such as the IMEI and the phone number; ANDROIDOS_ANSERVER.A gathers the device IMEI and IMSI; many listed mobile malware families collect IMEI, IMSI, ICCID, MEID, serial number, phone number, MAC address, IP address, carrier, MCC/MNC, and related device/network identifiers.
Anubis can exfiltrate files encrypted with the ransomware module from the device and can modify external storage. BusyGasper can collect images stored on the device and browser history. CHEMISTGAMES can collect files from the filesystem and account information from Google Chrome.
Examples in the content include: 'Riltok can access and upload the device's contact list to the command and control server,' 'Rotexy can access and upload the contacts list to the command and control server,' and multiple entries stating malware can 'exfiltrate' contacts.
21 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Nation-state mobile surveillanceware mentioned as a comparison for similar behavior.
Android surveillanceware used to target government officials, diplomats, military personnel, and activists, exfiltrating sensitive data such as letters, internal government communications, travel information, IDs, passports, GPS coordinates, legal and medical documents, developer information, and military/government photos.
Android malware that can record and take pictures using front and back cameras.
Android spyware that can selectively delete incoming SMS messages based on sender or content.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.