The cleanest public bridge is a CarbonSteal and HenBox server address that also communicated with an OS X backdoor FireEye had associated with GREF in 2014.
HenBox
HenBox is an Android spyware family used for targeted surveillance and cyberespionage.
HenBox
Family profile
HenBox is an Android spyware family used for targeted surveillance and cyberespionage. Publicly identified in early 2018, its known samples date back to late 2015. It is associated with the China-linked PKPLUG espionage cluster and primarily targets Uyghurs, particularly in Xinjiang, with additional targeting of Xiaomi devices running MIUI.
HenBox collects personal and device information, contacts, location data, and information about installed or running applications and processes. It intercepts SMS messages, harvests outgoing telephone numbers beginning with China's country code, and steals data from messaging, communication, and social media applications, including WeChat, WhatsApp, Telegram, Facebook, LINE, Viber, and Skype. It can also access the device's microphone and cameras.
HenBox has been distributed through third-party Android application stores while masquerading as VPN software or Android system applications. Some variants embed and install a legitimate decoy application alongside the malware to preserve the appearance of expected functionality. It hides its launcher icon and uses obfuscation, compression, and encryption to conceal components and configuration data. Registered broadcast receivers trigger execution following events such as device startup, SIM-state changes, application installation, time changes, and connectivity changes. It also responds to Xiaomi smart-home alerts, providing an additional event-triggered execution mechanism.
Capabilities
- Defense Evasion
- Exfiltration
- Persistence
- Reconnaissance
Samples
Recent samples
1 sandbox sample in the Derp library, newest 1 shown
Reported operators
Threat actors
2 named in public reportingIn early 2018, Unit 42 discovered a new Android malware family that we named ‘HenBox’... HenBox often masquerades as legitimate Android apps... Once installed, HenBox steals information from the device... It can also access the phone’s microphone and cameras.
MITRE ATT&CK
HenBox in ATT&CK
11 distinct techniquesReporting
Research mentioning HenBox
A new APT uses DLL side-loads to “KilllSomeOne” | SOPHOS
Sophos has identified a new PlugX USB worm variant spreading through removable media in outbreaks across Papua New Guinea, Ghana, Mongolia, Zimbabwe, and Nigeria, using DLL sideloading with legitimate AvastSvc.exe, a malicious wsc.dll, and an encrypted PlugX payload. The malware hides files on infected USB drives, gathers host reconnaissance, and steals Office and PDF documents up to 300 MB, storing them in encrypted form under RECYCLER.BIN with base64-obfuscated filenames before attempting exfiltration to infrastructure including 45.142.166[.]112. The activity aligns with the long-running PKPLUG espionage cluster, which researchers have previously attributed with high confidence to a Chinese nation-state adversary targeting victims in and around Southeast Asia, including Xinjiang, Mongolia, Myanmar, and Taiwan. Earlier reporting tied PKPLUG to malware families including PlugX, Poison Ivy, 9002, Zupdax, Farseer, and the Android spyware HenBox, and documented overlapping infrastructure, DLL sideloading, registry-based persistence, and surveillance-focused collection against regional targets, reinforcing the assessment that the new worm is part of a broader intelligence-gathering campaign.
A border-hopping PlugX USB worm takes its act on the road | SOPHOS
Chinese PlugX Malware Hidden in Your USB Devices?
Black Basta Ransomware Gang Infiltrates Networks via QAKBOT, Brute Ratel, and Cobalt Strike
Cyble - Fake Income Tax Application Targets Indian Taxpayers
Researchers identified an Android malware app named iMobile that impersonates India’s Income Tax Department and targets Indian taxpayers through phishing, harvesting sensitive data including PAN, Aadhaar, bank account information, debit card details, and internet banking credentials. The app also seeks extensive dangerous permissions and attempts to set itself as the device’s default SMS application, giving it the ability to read, receive, and send text messages while monitoring phone state and usage data. Analysis showed the stolen banking and internet-banking information was uploaded to the command-and-control endpoint jsig.quicksytes[.]com/MC/NN180521/mc.php, and the sample used string deobfuscation and hardcoded artifacts including an Indian mobile number. The campaign reflects a broader mobile threat pattern documented in MITRE ATT&CK T1636.004, where malicious apps abuse SMS access to intercept messages, including one-time passcodes and transaction alerts, to support credential theft, financial fraud, and account takeover.
Farseer: Previously Unknown Malware Family bolsters the Chinese armoury
Attackers used spear-phishing emails with TinyURL links and an actor-controlled redirection server to deliver the 9002 Trojan from a Google Drive-hosted ZIP archive. The redirection chain embedded a target email address and destination URL in base64-encoded parameters, apparently to track victim clicks, and one lure targeted a legitimate Myanmar politician and human rights activist. The downloaded executable posed as a PowerPoint file, displayed a Myanmar-related conference decoy, and installed malware through DLL sideloading by abusing a legitimate RealNetworks executable. Researchers linked the campaign’s infrastructure and beaconing artifacts to broader activity associated with Poison Ivy, PlugX, Zupdax, HenBox, and the later-identified Farseer malware family. Farseer shared tradecraft including DLL sideloading with signed binaries, encrypted and compressed payloads, obfuscated configuration data, registry persistence, and command-and-control over domains such as update.tcpdo[.]net, honor2020[.]ga, and up.outhmail[.]com. The overlapping infrastructure and Myanmar- and Southeast Asia-themed lures indicate a sustained intrusion set focused on targets in Myanmar, Taiwan, and the wider region.