Add Quark malware analysis report for Sova - #957
Merged
Merged
Conversation
Adds a report-only entry for Sova (S1062), an Android banking trojan first surfaced in mid-2021 and now known to have rebranded to Nexus in early 2023. Quark flagged 14 of 14 Sova samples as high-risk (detection rate 100%). Three MITRE ATT&CK Mobile techniques were confirmed with attacker- namespace evidence, all reached via the same C2 ping-response handler Lcom/tapston/burgerking/service/worker/PingTasks;onPingReceived inside a fake BurgerKing carrier sample: - T1426 System Information Discovery — reading phone number + IMEI - T1582 SMS Control — dispatching outbound SMS through ContexStartExtensionsKt.sendSMS - T1616 Call Control — placing outbound calls via ACTION_CALL intent The 16 remaining MITRE techniques documented for S1062 are classified in coverage-gap notes: 7 same-parent-method structural limits (each tested with a candidate two-API rule), 3 runtime / network-only behaviours, 3 sample-cohort gaps (v5 ransomware / clipboard hijack / packing), 2 library-attributed patterns, 1 install-time impersonation. No new Quark rule is generated in this run. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## master #957 +/- ##
=======================================
Coverage 80.29% 80.29%
=======================================
Files 82 82
Lines 7190 7192 +2
=======================================
+ Hits 5773 5775 +2
Misses 1417 1417
Flags with carried forward coverage won't be shown. Click here to find out more. ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
haeter525
self-requested a review
July 28, 2026 17:23
Three review-driven fixes: 1. The T1582 SMS Control image URL was a hand-typed placeholder returning 404. Re-upload the local behavior-map PNG to imgbb and point the report at the new URL. 2. Use "Sova" as the family name in the narrative for consistency; keep "S.O.V.A." only inside the official MITRE link text where it is the S1062 canonical name. 3. Rewrite the coverage-gap group heading from "Same-parent-method structural limit (Quark's Stage-3 requirement)" into plain language. The prior wording could read as if the APIs were not called at all, and used a Quark internal-stage term readers do not necessarily know. New wording explains that the two APIs ARE both called, but from different helper methods, and states in one sentence why Quark's rule matching insists on one shared parent function (register-passing between the two calls has to be traceable within a single method). Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
The prior wording claimed Quark only matches rules when both APIs are called from a single method. That is inaccurate: Quark's method_recursive_search (quark/core/quark.py, MAX_SEARCH_LAYER = 3) walks up the call graph looking for a mutual parent that transitively reaches both APIs. The reason Sova's accessibility / notification techniques do not match is that Sova's dispatcher-plus-tasks pattern puts the two APIs in separate Task.executeTaskOn methods whose shared parent (AccessibilityService.onAccessibilityEvent) sits more than 3 layers above the API sites, so Quark's bounded traversal hits its depth limit first. Rewrite the group heading to name the actual mechanism, cite the MAX_SEARCH_LAYER constant so readers can locate it, and back one technique (T1516 Input Injection) with the empirically observed caller-site list from sample 724a5617... . Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
The paragraph explaining Quark's 3-layer traversal limit ran eight lines, and the seven bullets under it each restated the same point in different words. Cut the paragraph to three lines and replace the bullets with a table listing only what differs per technique: the two APIs and their nearest shared caller. Also correct the T1516 call-site counts. The earlier text said 5 and 14; re-running the caller lookup on sample 724a5617 gives 6 and 12 Sova-authored call sites, since one findAccessibilityNodeInfosByText site and two performAction sites are in AndroidX support code. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
The sentence describing why the call-depth limit blocks these rules was hard to follow. State it directly: each API sits in a different Task helper, and the only method calling both is the dispatcher at the top, more than 3 layers up. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Replace the paragraph with the maintainer's wording. It states the limitation from the reader's point of view: the dispatcher triggers the techniques, the APIs sit in helpers more than 3 layers down, Quark stops at 3 layers for performance, and the limitation is being worked on. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
haeter525
approved these changes
Jul 31, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Sova Malware Family Analysis Report
This report analyses the Sova malware family using Quark's rule classification. Sova is an Android banking trojan first surfaced in mid-2021, distributed as trojanised carrier apps (fake BurgerKing, cryptocurrency wallets, delivery apps) that abuse Accessibility services to overlay banking / crypto exchange UIs, harvest credentials, intercept SMS one-time passwords, and — in the v5 branch — encrypt on-device files as ransomware. This run did not generate a new rule for Sova: the family's distinctive bytecode patterns (device-fingerprint queries and outbound-call intents from a single C2-message dispatcher) are already covered by Quark's existing rule set. Check here for the rule set details.
Quark's rule classification flagged 14 of 14 Sova samples as high-risk in this experiment (detection rate 100%). Benign-cohort false-positive rate was not measured here. See tested APKs below.
Identified Well-Known Threats
This section uses MITRE ATT&CK Mobile as its reference taxonomy, anchored to the S1062 S.O.V.A. software entry. Of the 19 techniques documented for the family, Quark's static bytecode analysis surfaces the 3 listed below; see the coverage-gap notes at the end of this section for why the other 16 are not demonstrated here.
ContexStartExtensionsKt.sendSMS) invoked by the C2 ping-response handler with an operator-supplied phone number and bodyIntent.ACTION_CALLintent with an operator-supplied phone number and invokingstartActivityfrom the same C2 ping-response handlerAll cluster representatives below were extracted from sample
724a56172f40177da76242ee169ac336b63d5df85889368d1531f593b658606b.apk(a fake BurgerKing carrier — packagecom.tapston.burgerking), chosen as the representative sample whose detected behaviors most fully cover the documented profile of Sova. The other 13 family samples were used to compute the detection-rate figure above.Each section below corresponds to one technique from the table above. Within each section we first quote the MITRE definition, then walk through the call sequence and list the underlying rules.
1. T1426 System Information Discovery
T1426 System Information Discovery — attack.mitre.org
Lcom/tapston/burgerking/service/worker/PingTasks;onPingReceived(an attacker-authored C2 ping-response handler inside the fake BurgerKing carrier app) is invoked whenever the operator's ping message arrives on the dispatcher; within this method the malware callsTelephonyManager.getLine1NumberandgetDeviceIdto read the victim's phone number and IMEI, then ships them back over the C2 socket as part of the ping ACK payload.Behaviors detected by Quark:
2. T1582 SMS Control
T1582 SMS Control — attack.mitre.org
The same
Lcom/tapston/burgerking/service/worker/PingTasks;onPingReceivedhandler routes a subset of operator commands to an attacker-authored Kotlin extension helperLcom/tapston/burgerking/extensions/context/ContexStartExtensionsKt;sendSMS, which wrapsSmsManager.sendTextMessageto inject outbound SMS on behalf of the operator. The dispatcher also references a content-URI delete primitive on the SMS/call-log providers to remove traces after sending.Behaviors detected by Quark:
3. T1616 Call Control
T1616 Call Control — attack.mitre.org
The same
Lcom/tapston/burgerking/service/worker/PingTasks;onPingReceivedhandler also handles the "place-call" operator command: it constructs anIntentwith theACTION_CALLaction, packs an operator-supplied phone number into the intent's URI viasetData, and invokesstartActivity— placing an outbound phone call without user consent.Behaviors detected by Quark:
Coverage-gap notes
The 16 MITRE techniques documented for Sova that this report does NOT demonstrate, grouped by the reason Quark could not confirm them on these samples:
The two APIs share a caller, but it sits deeper than Quark searches (7) — While the techniques below are triggered by Sova's service dispatcher, the actual APIs are hidden in helper functions more than 3 layers deep. For performance reasons, Quark does not search beyond 3 layers by default. As a result, these techniques are currently not detected by Quark, but we are actively working on addressing this limitation.
AccessibilityNodeInfo.findAccessibilityNodeInfosByText(6 Sova call sites)AccessibilityNodeInfo.performAction(12 Sova call sites)AppAccessibilityService.onAccessibilityEventAccessibilityEvent.getEventTypeAccessibilityEvent.getTextAppAccessibilityService.onAccessibilityEventWindowManager.addView(TYPE_APPLICATION_OVERLAY)WebView.loadUrlStatusBarNotification.getPackageNameStatusBarNotification.getNotificationNotificationListenerService.onNotificationPostedContext.getPackageManagerPackageManager.setComponentEnabledSettingDevicePolicyManager.isAdminActiveIntent.putExtra(device-admin request)Intent.<init>(ACTION_UNINSTALL_PACKAGE)Context.startActivityRuntime / network-only behavior (3) — bytecode analysis cannot capture these because the malicious intent lives in runtime C2 messages, not in distinct API pairs.
Socket.connect/HttpURLConnection, indistinguishable in bytecode from a legitimate app.Sample cohort does not exercise the behavior (3)
ClipboardManagerreferences in this cohort all fire inside bundled utility libraries (WhatsApp clones, React Native / Flutter clipboard modules) rather than in attacker code, so the Sova-authored clipboard-swap logic is not present in these samples.Behavior confirmed by Quark but attributed to bundled library (2)
PackageManager.getInstalledApplicationsandgetPackageInfofire in Sova's samples but always inside the Getui push SDK (Lcom/igexin/push/…), which uses the same API to build push-targeting maps. Sova likely reuses the SDK's cache rather than calling the primitive itself.Lcom/horcrux/svg/SvgView(react-native-svg rendering), not attacker code. Sova's actual screen capture usesAccessibilityService.takeScreenshot, a single-API surface with the same limitation as the group above.Runtime impersonation (1)
List of Tested APKs
The table below lists the APKs we tested.