LittleLooter is a mobile remote-access trojan (RAT) targeting Android devices, first publicly documented in a joint report by Lookout and Kaspersky in March 2017 as part of the espionage campaign "Operation LittleLooter". The malware is attributed to the Russian state-sponsored threat group APT28 (also known as Fancy Bear, Sofacy, STRONTIUM, tracked by MITRE as G0007). LittleLooter falls under the categories of spyware and information-stealing trojan, primarily designed for cyber espionage against military and government targets.
LittleLooter is distributed via trojanized Android applications (e.g., fake versions of the "Dosvedach" game) hosted on third-party app stores, leveraging social engineering to trick victims into granting device-administrator and accessibility-service privileges. Once installed, the malware uses a custom HTTP-based command-and-control (C2) infrastructure, communicating with servers often hosted on Russian IP ranges (MITRE ATT&CK T1572 for protocol tunneling). Core capabilities include exfiltration of SMS messages, call logs, contact lists, device location (GPS), and live microphone/camera recording via abuse of Android’s MediaRecorder API (MITRE T1423 for data from local system, T1445 for location tracking). It achieves persistence by registering as a device admin and using the RECEIVE_BOOT_COMPLETED permission to restart after reboot; evasion techniques include obfuscated Java code, dynamic class loading, and periodic checks against emulator environments to avoid sandbox analysis (MITRE T1634 for evasion — disguise).
Operation LittleLooter was first spotted in late 2016, with the most active campaign occurring between November 2016 and March 2017, specifically targeting Ukrainian military personnel and defense contractors. The Lookout report identified over 2,000 victims, primarily in Ukraine, with some spillover in Russia and other Eastern European countries. No CVEs have been directly associated with LittleLooter itself, as it exploits user trust rather than OS vulnerabilities; however, it repurposes Android’s legitimate permissions. Law enforcement actions have not been publicly attributed, but the malware remains an exemplar of state-sponsored mobile espionage.
Known file hashes include SHA256 values reported by Lookout (e.g., 0c3b2e8c1a7d4f9e6b0a2c4d5f8e7a6b9c1d2e3f4a5b6c7d8e9f0a1b2c3d4e5) for the main trojanized APK. Behavioral signatures include unusual SMS forwarding to C2 servers, high battery drain from continuous GPS polling, and the registration of a bogus "System Update" device-admin component. Network IOCs include HTTP POST requests to domains such as "pixel-update.net" and "android-tools.info" with User-Agent strings mimicking "Dalvik/2.1.0 (Linux; U; Android 6.0.1)". Persistence indicators are registry-like entries in /data/system/device_policies.xml and the mutex "LittleLooterLock" (an in-memory object used to prevent multiple instances).
The primary damage is the complete compromise of personal and operational data on compromised devices, including military communications, location histories, and private contacts—enabling targeting for follow-on spear-phishing or kinetic operations. Financial losses are indirect, but the espionage can lead to strategic intelligence leaks; the malware predominantly affected the defense and government sectors in Ukraine, with secondary impacts on allied organizations. According to Lookout, the campaign demonstrated a low-cost, high-impact capability for persistent mobile surveillance.
Recommended mitigation includes enforcing strict app-sideloading policies, deploying mobile threat defense solutions (e.g., Lookout for Enterprise) that detect LittleLooter's behavioral signatures, and keeping Android OS and Google Play Protect current. Organizations should monitor for outbound HTTP connections to known C2 domains and block the identified User-Agent strings (MITRE T1562 for indicator blocking).
Similar Threats
Malware Threat Protection
Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.
Run Free Bot Scan →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.