From 420b38a3b6c981e96c45c46383064ca83b70c03f Mon Sep 17 00:00:00 2001 From: Shaun Dang Date: Mon, 17 Aug 2026 18:41:29 +0800 Subject: [PATCH] docs: unify malware family report headings and parent doc title - Standardize all family section headings to ` Malware Family Analysis Report` - Fix casing (anubis/godfather/tanglebot -> Anubis/GodFather/TangleBot; Brata -> BRATA) - Sync in-body family names to the same casing (URLs untouched) - Rename parent doc title to `Quark Android Malware Family Analysis Reports` - Update README report links to the new anchors Rebased onto latest master to resolve conflicts. --- README.md | 30 ++++++------- docs/source/malware_report.rst | 82 +++++++++++++++++----------------- 2 files changed, 56 insertions(+), 56 deletions(-) diff --git a/README.md b/README.md index 54b5254c..0a4026fc 100644 --- a/README.md +++ b/README.md @@ -79,21 +79,21 @@ | Family | Summary | Signature Behaviors | Report | |-------------|----------------------------------------------------|--------------------------|--------| -| DroidKungFu | Privilege escalation with C2 control. | 1. Gain unlimited access to a device.
2. Install/Uninstall additional apps.
3. Forward confidential data. | [View](https://quark-engine.readthedocs.io/en/latest/malware_report.html#new-quark-rules-for-droidkungfu) | -| GoldDream | SMS/call log exfiltration with remote C2 commands. | 1. Monitor SMS messages and phone calls.
2. Upload SMS messages and phone calls to remote servers. | [View](https://quark-engine.readthedocs.io/en/latest/malware_report.html#new-quark-rules-for-golddream) | -| SpyNote | Credential theft and device surveillance via RAT. | 1. Take screenshots.
2. Simulate user gestures.
3. Log user input.
4. Communicate with C2 servers. | [View](https://quark-engine.readthedocs.io/en/latest/malware_report.html#new-quark-rules-for-spynote) | -| DawDropper | Dropper that installs banking trojans for financial theft. | 1. Download APKs from remote servers.
2. Install additional APKs. | [View](https://quark-engine.readthedocs.io/en/latest/malware_report.html#new-quark-rules-for-dawdropper) | -| SLocker | Android ransomware locking/encrypting devices. | 1. Lock the device with an overlay screen. | [View](https://quark-engine.readthedocs.io/en/latest/malware_report.html#new-quark-rules-for-slocker) | -| PhantomCard | NFC relay–based financial fraud. | 1. Communicate with C2 servers.
2. Read the payment data of NFC cards.
3. Captures PINs of NFC cards through deceptive screens. | [View](https://quark-engine.readthedocs.io/en/latest/malware_report.html#new-quark-rules-for-phantomcard) | -| ToxicPanda | Banking trojan enabling on-device fraud. | 1. Abuse Accessibility.
2. Remote device control.
3. Intercept OTP. | [View](https://quark-engine.readthedocs.io/en/latest/malware_report.html#new-quark-rules-for-toxicpanda) | -| Hydra | Banking trojan using overlay attacks. | 1. Overlay credential theft.
2. Accessibility abuse.
3. Steal OTP/cookies. | [View](https://quark-engine.readthedocs.io/en/latest/malware_report.html#new-quark-rules-for-hydra) | -| SharkBot | Banking trojan targeting financial credentials and transactions. | 1. Abuse Accessibility services.
2. Perform overlay attacks to steal credentials.
3. Intercept SMS messages (OTP). | [View](https://quark-engine.readthedocs.io/en/latest/malware_report.html#new-quark-rules-for-sharkbot) | -| Antidot | Banking trojan disguised as legitimate updates for financial data theft. | 1. Intercept SMS messages (OTP).
2. Log user input (keylogging).
3. Enable remote control via C2. | [View](https://quark-engine.readthedocs.io/en/latest/malware_report.html#new-quark-rules-for-antidot) | -| Arsink | Banking trojan focusing on credential and financial data exfiltration. | 1. Steal sensitive data from device.
2. Intercept SMS messages (OTP). | [View](https://quark-engine.readthedocs.io/en/latest/malware_report.html#new-quark-rules-for-arsink) | -| TrickMo | Banking trojan using overlay attacks and accessibility abuse for credential theft. | 1. Overlay attacks to steal banking credentials.
2. Intercept SMS for 2FA bypass.
3. Screen recording and accessibility abuse.
4. Dynamic payload loading via reflection. | [View](https://quark-engine.readthedocs.io/en/latest/malware_report.html#new-quark-rules-for-trickmo) | -| Anubis | Banking trojan with RAT capabilities. | 1. Overlay credential theft.
2. Keylogging.
3. Intercept SMS (OTP).
4. Remote control via C2. | [View](https://quark-engine.readthedocs.io/en/latest/malware_report.html#new-quark-rules-for-anubis) | -| GodFather | Banking trojan targeting financial credentials through overlay and accessibility abuse. | 1. Perform overlay attacks to steal credentials.
2. Abuse Accessibility services.
3. Intercept SMS messages (OTP).
4. Steal banking credentials and sensitive data. | [View](https://quark-engine.readthedocs.io/en/latest/malware_report.html#new-quark-rules-for-godfather) | -| TangleBot | SMS-based Android malware stealing personal and financial data. | 1. Spread through SMS phishing links.
2. Control device interactions and overlay screens.
3. Access SMS, contacts, call logs, camera, and microphone.
4. Steal account and financial information. | [View](https://quark-engine.readthedocs.io/en/latest/malware_report.html#new-quark-rules-for-tanglebot) | +| DroidKungFu | Privilege escalation with C2 control. | 1. Gain unlimited access to a device.
2. Install/Uninstall additional apps.
3. Forward confidential data. | [View](https://quark-engine.readthedocs.io/en/latest/malware_report.html#droidkungfu-malware-family-analysis-report) | +| GoldDream | SMS/call log exfiltration with remote C2 commands. | 1. Monitor SMS messages and phone calls.
2. Upload SMS messages and phone calls to remote servers. | [View](https://quark-engine.readthedocs.io/en/latest/malware_report.html#golddream-malware-family-analysis-report) | +| SpyNote | Credential theft and device surveillance via RAT. | 1. Take screenshots.
2. Simulate user gestures.
3. Log user input.
4. Communicate with C2 servers. | [View](https://quark-engine.readthedocs.io/en/latest/malware_report.html#spynote-malware-family-analysis-report) | +| DawDropper | Dropper that installs banking trojans for financial theft. | 1. Download APKs from remote servers.
2. Install additional APKs. | [View](https://quark-engine.readthedocs.io/en/latest/malware_report.html#dawdropper-malware-family-analysis-report) | +| SLocker | Android ransomware locking/encrypting devices. | 1. Lock the device with an overlay screen. | [View](https://quark-engine.readthedocs.io/en/latest/malware_report.html#slocker-malware-family-analysis-report) | +| PhantomCard | NFC relay–based financial fraud. | 1. Communicate with C2 servers.
2. Read the payment data of NFC cards.
3. Captures PINs of NFC cards through deceptive screens. | [View](https://quark-engine.readthedocs.io/en/latest/malware_report.html#phantomcard-malware-family-analysis-report) | +| ToxicPanda | Banking trojan enabling on-device fraud. | 1. Abuse Accessibility.
2. Remote device control.
3. Intercept OTP. | [View](https://quark-engine.readthedocs.io/en/latest/malware_report.html#toxicpanda-malware-family-analysis-report) | +| Hydra | Banking trojan using overlay attacks. | 1. Overlay credential theft.
2. Accessibility abuse.
3. Steal OTP/cookies. | [View](https://quark-engine.readthedocs.io/en/latest/malware_report.html#hydra-malware-family-analysis-report) | +| SharkBot | Banking trojan targeting financial credentials and transactions. | 1. Abuse Accessibility services.
2. Perform overlay attacks to steal credentials.
3. Intercept SMS messages (OTP). | [View](https://quark-engine.readthedocs.io/en/latest/malware_report.html#sharkbot-malware-family-analysis-report) | +| Antidot | Banking trojan disguised as legitimate updates for financial data theft. | 1. Intercept SMS messages (OTP).
2. Log user input (keylogging).
3. Enable remote control via C2. | [View](https://quark-engine.readthedocs.io/en/latest/malware_report.html#antidot-malware-family-analysis-report) | +| Arsink | Banking trojan focusing on credential and financial data exfiltration. | 1. Steal sensitive data from device.
2. Intercept SMS messages (OTP). | [View](https://quark-engine.readthedocs.io/en/latest/malware_report.html#arsink-malware-family-analysis-report) | +| TrickMo | Banking trojan using overlay attacks and accessibility abuse for credential theft. | 1. Overlay attacks to steal banking credentials.
2. Intercept SMS for 2FA bypass.
3. Screen recording and accessibility abuse.
4. Dynamic payload loading via reflection. | [View](https://quark-engine.readthedocs.io/en/latest/malware_report.html#trickmo-malware-family-analysis-report) | +| Anubis | Banking trojan with RAT capabilities. | 1. Overlay credential theft.
2. Keylogging.
3. Intercept SMS (OTP).
4. Remote control via C2. | [View](https://quark-engine.readthedocs.io/en/latest/malware_report.html#anubis-malware-family-analysis-report) | +| GodFather | Banking trojan targeting financial credentials through overlay and accessibility abuse. | 1. Perform overlay attacks to steal credentials.
2. Abuse Accessibility services.
3. Intercept SMS messages (OTP).
4. Steal banking credentials and sensitive data. | [View](https://quark-engine.readthedocs.io/en/latest/malware_report.html#godfather-malware-family-analysis-report) | +| TangleBot | SMS-based Android malware stealing personal and financial data. | 1. Spread through SMS phishing links.
2. Control device interactions and overlay screens.
3. Access SMS, contacts, call logs, camera, and microphone.
4. Steal account and financial information. | [View](https://quark-engine.readthedocs.io/en/latest/malware_report.html#tanglebot-malware-family-analysis-report) | | BRATA | Banking trojan with remote control and anti-analysis capabilities. | 1. Perform overlay attacks to steal banking credentials.
2. Abuse Accessibility services for device control.
3. Intercept SMS messages (OTP).
4. Execute factory reset or device wipe commands. | [View](https://quark-engine.readthedocs.io/en/latest/malware_report.html#brata-malware-family-analysis-report) | | Cerberus | Banking trojan targeting financial credentials through overlay and device control. | 1. Perform overlay attacks to steal credentials.
2. Abuse Accessibility services.
3. Log user input (keylogging).
4. Enable remote control via C2. | [View](https://quark-engine.readthedocs.io/en/latest/malware_report.html#cerberus-malware-family-analysis-report) | | SuperCardX | NFC relay malware enabling contactless payment fraud. | 1. Read NFC payment card data.
2. Relay NFC transactions to attacker-controlled devices.
3. Communicate with C2 servers.
4. Facilitate unauthorized contactless payments. | [View](https://quark-engine.readthedocs.io/en/latest/malware_report.html#supercardx-malware-family-analysis-report) | diff --git a/docs/source/malware_report.rst b/docs/source/malware_report.rst index e695ec17..f14151ce 100644 --- a/docs/source/malware_report.rst +++ b/docs/source/malware_report.rst @@ -1,9 +1,9 @@ -##################################### -Quark Android Malware Analysis Report -##################################### +############################################# +Quark Android Malware Family Analysis Reports +############################################# -New Quark Rules For DroidKungFu -=============================== +DroidKungFu Malware Family Analysis Report +========================================== New Quark rules (#00212 - #00233) are now available. These rules target `DroidKungFu `__, a malware family that gains unlimited access to a device, installs and uninstalls Apps, and forwards confidential data. Check `here `__ for the rule details. @@ -642,8 +642,8 @@ The table below lists the APKs we tested. | | 4BA33232F07D0EAE2648A6DF5B3009484CFDBDA6E57D8A0B221D215EC5300F | +-----+----------------------------------------------------------------+ -New Quark Rules For GoldDream -=============================== +GoldDream Malware Family Analysis Report +======================================== New Quark rules (#00234 - #00237) are now available. These rules target `GoldDream `__, a malware family that monitors SMS messages and phone calls and uploads them to remote servers. Check `here `__ for the rule details. @@ -738,8 +738,8 @@ The table below lists the APKs we tested. +-------+------------------------------------------------------------------+ -New Quark Rules For SpyNote -=========================== +SpyNote Malware Family Analysis Report +====================================== New Quark rules (#238 - #242) are now available. These rules target `SpyNote `_\ , a malware family that takes screenshots, simulates user gestures, logs user input, and communicates with C2 servers. Check `here `_ for the rule details. @@ -853,8 +853,8 @@ The table below lists the APKs we tested. - eec5096dfca6824317863f9225c29f6c4b3442c48fefa62dc382e3569bca5a60 -New Quark Rules For DawDropper -=============================== +DawDropper Malware Family Analysis Report +========================================= New Quark rules (#243 - #245) are now available. These rules target `DawDropper `_\ , a malware family that downloads and installs additional APKs. Check `here `_ for the rule details. @@ -938,8 +938,8 @@ The table below lists the APKs we tested. - d5ac8e081298e3b14b41f2134dae68535bcf740841e75f91754d3d0c0814ed42 -New Quark Rules For SLocker -=============================== +SLocker Malware Family Analysis Report +====================================== New Quark rule (#246) is now available. This rule targets `SLocker `_\ , a malware family that locks the device with an overlay screen. Check `here `_ for the rule details. @@ -1009,8 +1009,8 @@ The table below lists the APKs we tested. - f3fcd84b4e92a52ae5b30df003b911f21b2ea4325f788d5a5decc08582d3fd40 -New Quark Rules For PhantomCard -=============================== +PhantomCard Malware Family Analysis Report +========================================== New Quark rules (#247 - #251) are now available. These rules target `PhantomCard `_\ , a malware family that communicates with C2 servers, reads the payment data of NFC cards, and captures PINs of NFC cards through deceptive screens. Check `here `_ for the rule details. @@ -1110,8 +1110,8 @@ The table below lists the APKs we tested. - e27579b92fcad2f4fe96db7b5e7a7cdc41754a7cd126fcaf598d3f8d8c21c0f5 -New Quark Rules For ToxicPanda -============================== +ToxicPanda Malware Family Analysis Report +========================================= New Quark rules (#00252 - #00262) are now available. These rules target `ToxicPanda `__, a malware family that steals financial data via deceptive overlays, remotely controls devices, intercepts one-time passwords, and stay active in the background. Check `here `__ for the rule details. @@ -1219,8 +1219,8 @@ The table below lists the APKs we tested. - fde931224d2e558e67ac8c9c0c1d0aac4f7562622a67870d6c3024bdeb851676 -New Quark Rules For Hydra -========================= +Hydra Malware Family Analysis Report +==================================== New Quark rule (#00263) is now available. This rule targets `Hydra `_, a banking trojan family that intercepts SMS messages to capture OTPs, performs overlay attacks to steal banking credentials, communicates with C2 servers for remote control, and collects device fingerprints for tracking. Check `here `_ for the rule details. @@ -1393,8 +1393,8 @@ The table below lists the APKs we tested. * - 18 - fe9cfc5046c583a7b28fa506cd33e636d27310b14240247625c693444a27336f -New Quark Rules For SharkBot -============================ +SharkBot Malware Family Analysis Report +======================================= New Quark rules (#00264 - #00265) are now available. These rules target `SharkBot `_ , a sophisticated Android malware family primarily designed for financial fraud. SharkBot leverages techniques such as overlay attacks and credential theft to compromise user accounts. It has been observed targeting banking applications and employs various evasion techniques to avoid detection. Check `here `_ for detailed rule information. @@ -1478,8 +1478,8 @@ The table below lists the APKs we tested. +-------+------------------------------------------------------------------+ -New Quark Rules For Antidot -=========================== +Antidot Malware Family Analysis Report +====================================== New Quark rules (#00266–#00270) are now available. These rules target `Antidot `__, an Android malware family known for stealing sensitive information and executing a wide range of malicious activities on infected devices. Antidot primarily targets banking applications and leverages multiple evasion and persistence techniques to avoid detection. Check `here `__ for the rule details. @@ -1618,8 +1618,8 @@ The table below lists the APKs we tested. +-------+------------------------------------------------------------------+ -New Quark Rules For Arsink -========================== +Arsink Malware Family Analysis Report +===================================== A new Quark rule (#00271) is now available. This rule targets `Arsink `__. The Arsink malware family is a type of Android malware that targets users through various malicious behaviors, including accessing sensitive device information, initiating phone calls, and extensive Accessibility Service abuse for UI automation. It is often disguised as a legitimate application to evade detection and gain unauthorized access to user data. See the `quark-rules repository `__ for the rule details. @@ -1781,8 +1781,8 @@ The table below lists the APKs we tested. +-------+------------------------------------------------------------------+ -New Quark Rules For TrickMo -=========================== +TrickMo Malware Family Analysis Report +====================================== New Quark rule (#00272) is now available. This rules target `TrickMo `__. See the `quark-rules repository `__ for the rule details. @@ -1941,14 +1941,14 @@ The table below lists the APKs we tested. +-------+------------------------------------------------------------------+ -New Quark Rules For anubis -========================== +Anubis Malware Family Analysis Report +===================================== -New Quark rule (#00273) is now available. This rule targets `anubis `__. Anubis is a sophisticated Android banking trojan that emerged around 2017, targeting financial institutions worldwide. It features overlay attacks to steal banking credentials, keylogging, screen recording, SMS interception, and ransomware capabilities. The malware is distributed through malicious apps on Google Play and phishing campaigns. +New Quark rule (#00273) is now available. This rule targets `Anubis `__. Anubis is a sophisticated Android banking trojan that emerged around 2017, targeting financial institutions worldwide. It features overlay attacks to steal banking credentials, keylogging, screen recording, SMS interception, and ransomware capabilities. The malware is distributed through malicious apps on Google Play and phishing campaigns. In the representative sample, Quark observed the following behaviors at the API level: use accessibility service to query UI elements, read SMS messages, audio recording via microphone, make outbound phone calls programmatically, read and decode file contents, and HTTP communication with remote server. Check `here `__ for the rule details. -With these rules, Quark is now able to identify the anubis malware family as high-risk. In our experiment, Quark achieved 100% accuracy and 100% precision. Please check :ref:`here ` for the APKs we tested. +With these rules, Quark is now able to identify the Anubis malware family as high-risk. In our experiment, Quark achieved 100% accuracy and 100% precision. Please check :ref:`here ` for the APKs we tested. Below is a summary report of a TrickMo sample (``13f00206aaed4612ce4655152b972aeb2787ca4133aeacc8c9acd8c4d38ea3f79.apk``). The report shows that Quark identified the sample as high-risk, with a list of behaviors as evidence. @@ -2072,12 +2072,12 @@ The table below lists the APKs we tested. | 13 | F57308A3D0A09D0DA95D9055EC76E3DCED8292B47FCD41FEF237EBF7C1AD5F03 | +-------+------------------------------------------------------------------+ -New Quark Rules For godfather -============================= +GodFather Malware Family Analysis Report +======================================== -New Quark rule (#00274) is now available. This rule targets `godfather `__. Check `here `__ for the rule details. +New Quark rule (#00274) is now available. This rule targets `GodFather `__. Check `here `__ for the rule details. -With these rules, Quark is now able to identify the godfather malware family as high-risk. In our experiment, Quark achieved **100% accuracy** and **100% precision**. Please check :ref:`here ` for the APKs we tested. +With these rules, Quark is now able to identify the GodFather malware family as high-risk. In our experiment, Quark achieved **100% accuracy** and **100% precision**. Please check :ref:`here ` for the APKs we tested. Identified Well-Known Threats ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ @@ -2241,12 +2241,12 @@ The table below lists the APKs we tested. +-------+------------------------------------------------------------------+ -New Quark Rules For tanglebot -============================= +TangleBot Malware Family Analysis Report +======================================== New Quark rule (#00275) is now available. This rule targets `TangleBot `__. Check `here `__ for the rule details. -With these rules, Quark is now able to identify the tanglebot malware family as high-risk. In our experiment, Quark achieved **100% accuracy** and **100% precision**. Please check :ref:`here ` for the APKs we tested. +With these rules, Quark is now able to identify the TangleBot malware family as high-risk. In our experiment, Quark achieved **100% accuracy** and **100% precision**. Please check :ref:`here ` for the APKs we tested. Identified Well-Known Threats ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ @@ -2383,12 +2383,12 @@ The table below lists the APKs we tested. +-------+------------------------------------------------------------------+ -Brata Malware Family Analysis Report +BRATA Malware Family Analysis Report ==================================== -Quark's existing rule set already detects the `brata `__ malware family — no new rule was required. Check `here `__ for the rule set. +Quark's existing rule set already detects the `BRATA `__ malware family — no new rule was required. Check `here `__ for the rule set. -With these rules, Quark is able to identify the brata malware family as high-risk. In our experiment, Quark achieved **100% accuracy** and **100% precision**. Please check :ref:`here ` for the APKs we tested. +With these rules, Quark is able to identify the BRATA malware family as high-risk. In our experiment, Quark achieved **100% accuracy** and **100% precision**. Please check :ref:`here ` for the APKs we tested. Identified Well-Known Threats ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~