Oblivion is an Android remote access trojan sold as a subscription-based malware offering and designed to lower the barrier to entry for surveillance and device takeover. It has been marketed openly with builder functionality that allows operators to generate trojanized Android applications, and it commonly relies on social engineering that imitates routine Android update or service prompts. A frequently reported infection vector is a fake Google Play update message that persuades victims to install the malware and grant dangerous permissions.
Once installed, Oblivion abuses Android Accessibility Services to obtain extensive control over the device and silently approve actions that would normally require user interaction. Documented capabilities include theft of SMS messages, including banking one-time codes, keylogging to capture passwords and PINs, covert remote control, and live screen viewing. It can present a fake system-update animation while an operator interacts with the device in the background, helping conceal malicious activity from the victim. Reporting also states that it can remotely unlock a phone after reboot, indicating deep post-compromise control and persistence-oriented behavior.
Oblivion is positioned as a scalable Android surveillance platform, with backend infrastructure reportedly built to manage large numbers of concurrent victims and optional anonymized operator access. It has been described as targeting a broad range of Android versions and as attempting to bypass OEM security layers across major Android distributions. The malware has also been linked in later reporting to the RedWing Android malware operation, which has been assessed as an evolved variant of the Oblivion family based on similarities in dropper and overlay components. Those reports further suggest possible links to Russian threat actors through the broader ecosystem around related variants, although direct attribution for Oblivion itself remains limited.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct techniques documented for this family, organized by ATT&CK tactic.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as the likely predecessor or closely related malware family to RedWing, based on similarities in the dropper and overlay mechanisms.
Referenced as the apparent malware family root or lineage for RedWing.
Rent-a-malware Android tool described as the apparent predecessor or variant family related to RedWing.
Referenced as a likely related malware family/variant due to similarities in the dropper stage and overlay mechanisms.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.