Names | Roaming Mantis MoqHao XLoader | |
Category | Malware | |
Type | Banking trojan, Info stealer, Miner | |
Description | (Kaspersky) The Roaming Mantis mobile banking trojan is roaming further afield than it ever has before. Recent analysis shows that the malware has rapidly evolved just in the past month. It’s now targeting Europe and the Middle East in addition to Asian countries. According to researchers, it’s following the cyber-zeitgeist by expanding its capabilities to include cryptomining (and iOS phishing). Roaming Mantis is a mostly-mobile malware which this year has been spreading via DNS hijacking. Potential victims are typically redirected to a malicious webpage that distributes a trojanized application that pretends to be either Facebook or Chrome. Once installed manually by users, a trojan banker will execute. | |
Information | <https://threatpost.com/roaming-mantis-swarms-globally-spawning-ios-phishing-cryptomining/132149/> <https://blog.trendmicro.com/trendlabs-security-intelligence/xloader-android-spyware-and-banking-trojan-distributed-via-dns-spoofing/> <https://blog.trendmicro.com/trendlabs-security-intelligence/a-look-into-the-connection-between-xloader-and-fakespy-and-their-possible-ties-with-the-yanbian-gang/> | |
MITRE ATT&CK | <https://attack.mitre.org/software/S0318/> | |
Malpedia | <https://malpedia.caad.fkie.fraunhofer.de/details/apk.roaming_mantis> <https://malpedia.caad.fkie.fraunhofer.de/details/apk.moqhao> <https://malpedia.caad.fkie.fraunhofer.de/details/apk.xloader> | |
AlienVault OTX | <https://otx.alienvault.com/browse/pulses?q=tag:Roaming%20Mantis> |
Last change to this tool card: 13 May 2020
Download this tool card in JSON format
Changed | Name | Country | Observed | ||
Other groups | |||||
Roaming Mantis | [Unknown] | 2017-Jun 2020 |
1 group listed (0 APT, 1 other, 0 unknown)
Thailand Computer Emergency Response Team (ThaiCERT) Follow us on![]() ![]() |
Report incidents |
|
![]() |
+66 (0)2-123-1234 | |
![]() |
report@thaicert.or.th | |
![]() |
Download PGP key |