EagleMsgSpy
Hunt this family in your stack
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
Techniques & procedures
2 distinct techniques documented for this family, organized by ATT&CK tactic.
Collection
2 techniques
Collection
The tool, which targets Android devices, reportedly requires physical access to a device for installation and collects extensive data, including SMS and third-party chat messages, screen and audio recording, call logs, device contacts, location data, and network activity.
Recent activity
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Android surveillance tool requiring physical access for installation and collecting SMS, chat messages, screen and audio recordings, call logs, contacts, location data, and network activity.
Android surveillance tool suspected to be used by Chinese police departments for lawful intercept-style data collection.
The version that knows your environment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.