ThaiCERT    ETDA    MDES
Report
Search
Home > List all groups > List all tools > List all groups using tool Roaming Mantis

Threat Group Cards: A Threat Actor Encyclopedia

Permanent link Tool: Roaming Mantis

NamesRoaming Mantis
MoqHao
XLoader
CategoryMalware
TypeBanking trojan, Info stealer, Miner
Description(Kaspersky) The Roaming Mantis mobile banking trojan is roaming further afield than it ever has before. Recent analysis shows that the malware has rapidly evolved just in the past month. It’s now targeting Europe and the Middle East in addition to Asian countries. According to researchers, it’s following the cyber-zeitgeist by expanding its capabilities to include cryptomining (and iOS phishing).

Roaming Mantis is a mostly-mobile malware which this year has been spreading via DNS hijacking. Potential victims are typically redirected to a malicious webpage that distributes a trojanized application that pretends to be either Facebook or Chrome. Once installed manually by users, a trojan banker will execute.
Information<https://threatpost.com/roaming-mantis-swarms-globally-spawning-ios-phishing-cryptomining/132149/>
<https://blog.trendmicro.com/trendlabs-security-intelligence/xloader-android-spyware-and-banking-trojan-distributed-via-dns-spoofing/>
<https://blog.trendmicro.com/trendlabs-security-intelligence/a-look-into-the-connection-between-xloader-and-fakespy-and-their-possible-ties-with-the-yanbian-gang/>
MITRE ATT&CK<https://attack.mitre.org/software/S0318/>
Malpedia<https://malpedia.caad.fkie.fraunhofer.de/details/apk.roaming_mantis>
<https://malpedia.caad.fkie.fraunhofer.de/details/apk.moqhao>
<https://malpedia.caad.fkie.fraunhofer.de/details/apk.xloader>
AlienVault OTX<https://otx.alienvault.com/browse/pulses?q=tag:Roaming%20Mantis>

Last change to this tool card: 13 May 2020

Download this tool card in JSON format

All groups using tool Roaming Mantis

ChangedNameCountryObserved

Other groups

 Roaming Mantis[Unknown]2017-Jun 2020 

1 group listed (0 APT, 1 other, 0 unknown)

Thailand Computer Emergency Response Team (ThaiCERT)
Electronic Transactions Development Agency

Follow us on

Facebook Twitter

Report incidents

Telephone +66 (0)2-123-1234
E-mail report@thaicert.or.th
PGP Download PGP key