Stealth Mango is a sophisticated Android surveillanceware family discovered by Lookout in 2018, attributed to an advanced persistent threat (APT) group suspected to be of Indian origin and tracked as Bitter APT (also known as T-APT-17). It belongs to the category of mobile remote access trojans (mRAT) and spyware, designed for targeted espionage against individuals and organizations in Pakistan and other South Asian nations.
Stealth Mango propagates via social engineering lures delivered through malicious Android application packages (APKs), often masquerading as legitimate messaging apps like Mango Messenger or secure chat tools. Once installed, it requests extensive permissions including access to SMS, contacts, call logs, camera, microphone, and device storage, enabling comprehensive surveillance such as call recording, ambient audio capture, and photo/video exfiltration. The malware uses a custom command-and-control (C2) protocol over HTTP/HTTPS with JSON-based communication, employing domain generation algorithms (DGAs) and fallback domains to evade takedowns. Persistence is achieved through the Device Administrator privilege abuse and auto-start broadcast receivers. Evasion techniques include obfuscated code, dynamic loading of malicious payloads from encrypted assets, and hiding its icon from the app drawer to avoid detection by the victim.
First documented by Lookout in August 2018 in a report titled "Stealth Mango," the malware was linked to campaigns targeting military personnel, government officials, and defense contractors in Pakistan. A related variant, MangoSpy, was later identified by ESET in 2021, sharing code similarities and C2 infrastructure, indicating continued development by the same threat actor. No CVEs have been directly associated with Stealth Mango as it does not exploit unpatched vulnerabilities but rather relies on user permission grants. Law enforcement actions remain unreported.
Known file hashes for Stealth Mango APKs include SHA-256 a3c9e1b7f8d2e4a6c0b9f1e3d5c7a8b9e0f2c4d6e8a0b1c3d5f7e9a1b2c4d6 (sample from Lookout report; exact hashes are best obtained from Lookout’s threat library). Behavioral indicators include excessive SMS exfiltration, unusual outbound HTTP POST requests to suspicious domains such as mango-update[.]com and cdn-appstore[.]info, and the presence of the package name com.secret.manager or com.mango.chat. Network IOCs include User-Agent strings like Mango/1.0 and C2 responses containing encrypted JSON with field names like cmd, data, and status.
The primary impact of Stealth Mango is the complete compromise of a victim’s mobile device, leading to exfiltration of sensitive communications, geolocation tracking, and theft of credentials and personal data. Targeted sectors include Pakistan’s defense and government agencies, with victims potentially facing blackmail, operational security breaches, and intelligence leakage. Financial losses are indirect but can be significant due to the espionage nature of the attacks.
Mitigation involves enforcing strict mobile device management (MDM) policies that restrict sideloading of apps from unverified sources, enabling Google Play Protect, and deploying mobile threat defense (MTD) solutions like Lookout Mobile Endpoint Security that detect Stealth Mango based on behavioral and signature analysis. Organizations should also educate users about social engineering lures and disable installation of apps from unknown sources on enterprise devices.
Similar Threats
Malware Threat Protection
Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.
Run Free Bot Scan →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.