DAAM
Malware⚠️ Overview
DAAM is an Android malware family first documented in August 2023 by researchers at CloudSEK, combining data theft and ransomware capabilities. It is attributed to unknown threat actors primarily targeting Indian users through malicious APK files disguised as legitimate apps, and falls under the categories of infostealer and mobile ransomware.
🔧 Technical Capabilities
DAAM propagates via third-party app stores and social engineering lures, often masquerading as popular messaging or utility apps. Once installed, it requests Accessibility Service permissions to gain extensive control over the device, enabling it to read on-screen content, intercept notifications, and prevent removal. The malware exfiltrates WhatsApp message databases, contact lists, and call logs to a remote C2 server, then encrypts files on the device using AES-256 and appends a .enc extension. It displays a ransom note demanding payment in cryptocurrency for decryption. Persistence is achieved through device administrator privileges and by hiding its icon from the app drawer. Evasion techniques include obfuscated code and dynamic loading of payloads to bypass Google Play Protect.
📜 History & Notable Incidents
First observed in June 2023 during a targeted campaign against Indian WhatsApp users, DAAM was publicly detailed in August 2023 by CloudSEK's threat research team. No CVEs are associated with this malware; it relies on social engineering rather than exploiting unpatched vulnerabilities. No law enforcement actions have been reported to date.
🔍 Detection Indicators
Known file hashes include SHA256: e3c0c1a2b3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0 (sample APK). Behavioral signatures include requests for AccessibilityService, repeated encryption of files with .enc extension, and connections to C2 domains such as damon[.]xyz and payment[.]daam[.]top. Mutex names and registry keys are not applicable on Android; instead, device admin package names like com.daam.helper are used.
☠️ Risk & Impact
DAAM causes permanent data loss through file encryption and exfiltrates sensitive WhatsApp conversations, contacts, and media, leading to privacy breaches and financial coercion. Affected sectors primarily include individual mobile users in India, with potential for lateral spread to enterprise devices if compromised phones access corporate resources. The ransom demand typically ranges from ₹10,000 to ₹50,000 (approx. $120–$600 USD).
🛡️ Mitigation
Users should avoid sideloading apps from untrusted sources and disable "Install from unknown apps" for browsers and messaging apps. Organizations can deploy mobile threat defense tools with behavior-based detection rules for AccessibilityService abuse and file encryption events, and enforce app whitelisting through MDM solutions.
Similar Threats
Malware Threat Protection
Is Your Site Protected Against Malware-Driven Bot Traffic?
Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.
Run Free Bot Scan →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.