Skip to main content
Mallory
MalwareUsed by 1 actor

DroidJack

DroidJack is an Android remote access trojan/spyware family. The provided content states it captures SMS data and call data, and can capture video using device cameras. In the documented 2015 Syria-focused intrusion operation attributed to "Group5," an Android APK masquerading as an Adobe Flash Player update (adobe_flash_player.apk, MD5 8EBEB3F91CDA8E985A9C61BEB8CDDE9D) was identified as DroidJack. Symantec is cited as assessing that DroidJack evolved from the older SandroRAT codebase. In that campaign, DroidJack was used against Syrian opposition targets and provided surveillance capabilities including SMS and call logging, contacts theft, file browsing, location tracking, and remote camera/microphone activation. The Android malware used the same command-and-control host as the associated Windows malware: 88.198.222.163 (Hetzner, Germany). High-confidence indicators and related infrastructure mentioned in the content include 88.198.222.163 and the APK MD5 8EBEB3F91CDA8E985A9C61BEB8CDDE9D.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

THREAT ACTORS

Groups observed using it

1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
Group5

"The APK is an instance of DroidJack. According to Symantec, this malware evolved from an older codebase known as SandroRAT."

via citizenlabcitizenlab.ca
MITRE ATT&CK

Techniques & procedures

7 distinct techniques documented for this family, organized by ATT&CK tactic.

Initial Access

1 technique
T1189Drive-by CompromiseEvidence1

"we uncovered a watering hole website with malicious programs, malicious PowerPoint files, and Android malware" ... "Group5 operated a website, assadcrimes[.]info that served as a watering hole for Android and Windows malware"

Persistence

1 technique
T1547Boot or Logon Autostart ExecutionEvidence1

"Boot Completed Allows the application to re-connect when the device restarts"; "starts the Controller Service when the phone boots"

T1547Boot or Logon Autostart ExecutionEvidence1

"Boot Completed Allows the application to re-connect when the device restarts"; "starts the Controller Service when the phone boots"

Stealth

2 techniques
T1036MasqueradingEvidence1
TacticStealth

"decoy application... displays images... while simultaneously infecting"; "malware masquerading as an Adobe Flash Player update notification"; "drops a file named dvm.gif to disk, renames it to dvm.exe"

T1564Hide ArtifactsEvidence1
TacticStealth

"Upon execution, the malware is installed and then hidden from the list of installed applications... Application icon will be removed... yet it will still be running in the background"

Collection

2 techniques
T1123Audio CaptureEvidence1

"spy on the computer user via the microphone"; "Remote camera and microphone"; "record calls"

T1125Video CaptureEvidence1

"spy on the computer user via the ... webcam"; "allow the operator to use the infected device’s camera to take pictures and record video"

T1219Remote Access ToolsEvidence1

"deliver two commonly available Remote Access Trojans (RATs): njRat and NanoCore RAT"; "The APK is an instance of DroidJack"

INDICATORS OF COMPROMISE

IOCs tracked for this family

3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.

View more in app
Network
2 tracked

IPs, domains, and DNS infrastructure linked to this family.

Hashes
1 tracked

File hashes (MD5, SHA-1, SHA-256) from samples and reports.

TypeValueLatest sighting
hash.md5●●●●●●●●●●●●View more in app5 months ago
ip.v4●●●●●●●●●●●●View more in app5 months ago
domain●●●●●●●●●●●●View more in app5 months ago
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching3

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution1

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping7

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.