Roaming Mantis

First seen
2018-03-01 00:00:00
Malware type
trojan
Family
Malware family
Last IoC activity
2026-07-11 08:25:30
Profile updated
2026-07-07 14:06:38

Targeted industries: financial-services retail-and-hospitality

Targeted regions: country_code:jp country_code:kr country_code:tw country_code:hk

Context

Roaming Mantis is an Android Trojan that has been predominantly spreading through DNS hijacking and smishing campaigns, targeting users mainly in Japan, South Korea, Taiwan, and Hong Kong. It is known for stealing credentials and distributing malicious software.

Reports & references

  • Kaspersky — 96250 (report)
  • kashifali.ca — Roaming Mantis Amplifies Smishing Campaign With Os Specific Android Malware (report)
  • hitcon.org — D2 S1 R1 (report)
  • malpedia.caad.fkie.fraunhofer.de — Apk.Roaming Mantis (report)
  • Kaspersky — 85607 (report)
  • Kaspersky — 105596 (report)
  • Kaspersky — 85178 (report)
  • systemweakness.com — A Strange Font Smishing That Changes Behaviour Based On User Agent And Abuses Duck Dns 1C1A45863Ff7 (report)
  • systemweakness.com — Investigating A Fake Mobile Payment Smishing That Abuses Duck Dns D07C72468Ba8 (report)

External references