GhostSpy
GhostSpy is an Android spyware/RAT malware family. The provided content describes it as a new Android malware capable of extensive device surveillance and remote control, including keylogging, screen capture, background audio and video recording, SMS theft, call log theft, GPS location tracking, and remote command execution. It is referenced as Android GhostSpy in ESET research tied to a targeted spyware campaign in Pakistan that used a fake dating application as a lure, with indicators of compromise published in an IoC repository. The content also links GhostSpy to Brazil through reporting that the actor or reseller known as "Go1ano developer" claimed to be a trusted partner for the GhostSpy spyware family in Brazil. Additional comparative reporting states GhostSpy is a known Android RAT that uses accessibility tree traversal for permission-granting workflows. High-confidence indicators explicitly present in the content include the hashes B15B1F3F2227EBA4B69C85BDB638DF34B9D30B6A and 8B103D0AA37E5297143E21949471FD4F6B2ECBAA, associated with the Pakistan-targeted campaign IoC repository.
Hunt this family in your stack
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
Groups observed using it
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Besides PhantomCard, "Go1ano developer" also claims to be the "trusted partner" of BTMOB, GhostSpy spyware families in Brazil.
Recent activity
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Android remote access trojan referenced as abusing AccessibilityService to automate permission granting via accessibility tree traversal (slower than the PoC described).
GhostSpy is an Android spyware that provides extensive surveillance capabilities, including keylogging, screen and audio capture, SMS and call log theft, GPS tracking, and remote command execution. It uses accessibility services and Device Admin APIs for persistence and anti-uninstall measures.
Spyware family marketed in Brazil by the same reseller actor discussed in the report.
The version that knows your environment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.