From 6f50555ccac52d91815e7bd63ac790d1c83f57a6 Mon Sep 17 00:00:00 2001 From: Shaun Dang Date: Thu, 20 Aug 2026 18:47:25 +0800 Subject: [PATCH] Add images and new malware entry to README --- README.md | 3 +++ 1 file changed, 3 insertions(+) diff --git a/README.md b/README.md index 54b5254c..9c6a822f 100644 --- a/README.md +++ b/README.md @@ -73,6 +73,8 @@ + + @@ -102,6 +104,7 @@ | AndroRat | Android remote access trojan for device surveillance. | 1. Record audio and capture video.
2. Track device location.
3. Steal files and device information.
4. Execute remote commands. | [View](https://quark-engine.readthedocs.io/en/latest/malware_report.html#androrat-malware-family-analysis-report) | | Sova | Android banking trojan distributed as trojanised carrier apps for credential theft and SMS fraud. | 1. Read device identifiers via the C2 ping-response handler.
2. Inject outbound SMS on operator command.
3. Place phone calls without user consent. | [View](https://quark-engine.readthedocs.io/en/latest/malware_report.html#sova-malware-family-analysis-report) | | EventBot | Banking trojan and infostealer targeting 200+ financial apps. | 1. Enumerate installed applications to pick targets.
2. Intercept incoming SMS via a broadcast receiver.
3. Exfiltrate SMS bodies over HTTP to defeat 2FA. | [View](https://quark-engine.readthedocs.io/en/latest/malware_report.html#eventbot-malware-family-analysis-report) | +| Skygofree | Android spyware designed for surveillance and sensitive data collection. | 1. Capture audio.
2. Access stored application data.
3. Download new code at runtime.
4. Capture video. | [View](https://quark-engine.readthedocs.io/en/latest/quark_rules.html#new-quark-rules-for-skygofree) | ## Quick Start