Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to malware
Malware

Overlay Phantom

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

MITRE ATT&CK

Techniques & procedures

6 distinct techniques documented for this family, organized by ATT&CK tactic.

Initial Access

1 technique
T1566PhishingEvidence1

The malware currently targets over 180 banking, finance, and cryptocurrency applications across 10 countries using embedded WebView-based HTML phishing overlays that are visually indistinguishable from the legitimate apps they impersonate.

Stealth

1 technique
T1036MasqueradingEvidence1

one package masquerades as the official Austrian government identity application, ID Austria . Meanwhile, another variant pretends to be the high-popularity consumer platform, TikTok . Subsequently, the dropper displays a convincing Google Play update notification.

Credential Access

1 technique
T1056Input CaptureEvidence1

It loads pre-built assets to display credential harvesting overlays seamlessly above authentic interfaces . As a result, users enter their passwords without noticing any anomalous behavior.

Collection

2 techniques
T1056Input CaptureEvidence1

It loads pre-built assets to display credential harvesting overlays seamlessly above authentic interfaces . As a result, users enter their passwords without noticing any anomalous behavior.

T1113Screen CaptureEvidence1

It leverages Android’s native MediaProjection API to capture the device screen constantly . Then, it compresses the visual assets into JPEG format to minimize bandwidth overhead .

Command and Control

2 techniques
T1071Application Layer ProtocolEvidence1

To execute this, the malware establishes a dedicated TCP connection to its backend server . Interestingly, the backend architecture does not rely on a single communication line . Instead, the malware separates traffic across three distinct non-standard ports . Specifically, port 9091 handles operator command execution . Meanwhile, port 9092 tracks basic device status reports . Finally, port 9090 manages the outgoing screen streaming data .

T1219Remote Access ToolsEvidence1

the command framework supports over 30 remote administrative commands . For example, operators can manipulate active clipboard items or simulate touch gestures . They can also trigger fake notification banners to force user interaction .

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping6

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.