Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
remote-access-implantcredential-stealer-activityloader-delivery-mechanismcommand-and-control-method

Android Malware Leveraging Legitimate Apps for Surveillance and Theft

Updated 3mo agoFirst seen Dec 22, 20252 sources

Threat actors have increasingly adopted sophisticated techniques to distribute Android malware by disguising malicious applications as legitimate ones on the Google Play Store and other platforms. Notably, the new Cellik Android RAT has been identified as turning legitimate Google Play apps into surveillance tools, enabling attackers to covertly monitor and exfiltrate sensitive user data. In parallel, operations involving the Wonderland SMS stealer have merged dropper, SMS theft, and RAT capabilities at scale, with attackers using fake Google Play Store pages, ad campaigns, and messaging apps to propagate malware, particularly targeting users in Uzbekistan. These campaigns often leverage Telegram for coordination and distribution, and employ advanced methods such as intercepting OTPs and exfiltrating contact lists to facilitate financial theft and evade detection.

The evolution of Android malware now includes the use of droppers that appear harmless but deploy malicious payloads locally after installation, even without an active internet connection. The Wonderland malware, attributed to the TrickyWonders group, demonstrates bidirectional command-and-control communication, allowing real-time execution of commands and theft of SMS messages. The convergence of these techniques highlights a growing trend in mobile threat operations, where attackers exploit the trust in legitimate app platforms and social engineering to compromise devices, steal credentials, and siphon funds from victims' bank accounts.

Share:
Android Malware Leveraging Legitimate Apps for Surveillance and Theft
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

3 events from the most recent confirmed update back to the earliest known activity.

3 EVENTS
Dec 22, 20256mo ago

Analysis links broader Android malware trend to Cellik and other families

Reporting highlighted a wider evolution in Android malware operations, noting the emergence of families including Cellik, Frogblight, and NexusRoute that combine capabilities such as RAT access, phishing, screen streaming, and malware-as-a-service delivery. This marked a broader escalation in mobile threat sophistication across multiple countries.

Threat actors scale Wonderland Android malware campaign in Uzbekistan

Researchers reported that the financially motivated TrickyWonders group was using dropper apps disguised as legitimate software to deliver the Wonderland SMS-stealing malware, primarily targeting users in Uzbekistan. The operation used fake Google Play pages, social media ads, and messaging apps to steal SMS messages, intercept OTPs, and drain victims' bank cards.

Researchers discover Cellik Android RAT abusing legitimate Play apps

A newly identified Android remote access trojan named Cellik was reported as covertly turning legitimate Google Play applications into surveillance tools to evade detection and monitor infected devices. The malware was described as part of a broader wave of increasingly sophisticated Android threats.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

16 LINKEDOpen in app
Organizations
4 linked
KasperskyiVerifyCYFIRMAGroup-IB
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.