Roaming Mantis
- First seen
- 2018-03-01 00:00:00
- Malware type
- trojan
- Family
- Malware family
- Last IoC activity
- 2026-07-11 08:25:30
- Profile updated
- 2026-07-07 14:06:38
Targeted industries: financial-services retail-and-hospitality
Targeted regions: country_code:jp country_code:kr country_code:tw country_code:hk
Context
Roaming Mantis is an Android Trojan that has been predominantly spreading through DNS hijacking and smishing campaigns, targeting users mainly in Japan, South Korea, Taiwan, and Hong Kong. It is known for stealing credentials and distributing malicious software.
Reports & references
- Kaspersky — 96250 (report)
- kashifali.ca — Roaming Mantis Amplifies Smishing Campaign With Os Specific Android Malware (report)
- hitcon.org — D2 S1 R1 (report)
- malpedia.caad.fkie.fraunhofer.de — Apk.Roaming Mantis (report)
- Kaspersky — 85607 (report)
- Kaspersky — 105596 (report)
- Kaspersky — 85178 (report)
- systemweakness.com — A Strange Font Smishing That Changes Behaviour Based On User Agent And Abuses Duck Dns 1C1A45863Ff7 (report)
- systemweakness.com — Investigating A Fake Mobile Payment Smishing That Abuses Duck Dns D07C72468Ba8 (report)