Skip to content

Mamont

Mamont is an Android banking Trojan family that emerged in late 2023 and became one of the most prevalent mobile banking malware families affecting users in Russia, the CIS, and other regional campaigns through 2024–2026.

Profile source: Mallory opens in a new tab

Mamont

Family profile

Mamont is an Android banking Trojan family that emerged in late 2023 and became one of the most prevalent mobile banking malware families affecting users in Russia, the CIS, and other regional campaigns through 2024–2026. It is actively developed, with numerous variants and both banker and dropper-classified samples observed in the wild. Mamont has been associated with large-scale Android banking Trojan activity and has repeatedly dominated mobile banker detections in industry telemetry.

Mamont is distributed through social-engineering lures rather than exploit-driven infection. Documented delivery schemes include fake parcel-tracking applications tied to fraudulent online storefronts and Telegram-based order scams, instant-message lures, fake offers in neighborhood or community chats, and trojanized Android applications such as a fake dating app targeting Uzbek-speaking users. Some variants use a multi-stage infection chain in which an initial Android dropper decrypts and installs a second-stage payload, including encrypted embedded APKs.

Once installed, Mamont requests extensive Android permissions related to SMS, phone state, calls, notifications, and background execution. Its core behavior centers on theft and abuse of financial communications. Observed capabilities include intercepting SMS messages, harvesting one-time codes, hijacking push notifications, collecting device and SIM information, enumerating installed applications, and extracting financial data from banking alerts. Certain variants parse multilingual SMS content for transaction and balance information. Mamont also supports remote command execution through command-and-control infrastructure, enabling operators to send SMS messages, place calls, issue USSD requests, retrieve recent messages, and trigger additional data collection.

Mamont also includes defense-evasion and post-compromise tradecraft. Operators can hide or alter the app icon, keep malicious logic running in the background, and use staged installation flows to transfer execution from a visible lure app to the real payload. Some variants expose custom prompts and image-upload interfaces that allow attackers to solicit additional victim data and support follow-on social-engineering fraud. These functions expand Mamont beyond simple OTP theft into broader account takeover and financial fraud operations.

Victimology is strongest for Android users in Russia and neighboring CIS markets, but localized campaigns have also targeted Uzbek-speaking users. Small businesses and individual consumers have both been targeted, especially where mobile devices are used for banking, order management, or receipt of transaction confirmations. Available reporting supports classifying Mamont as a mature, modular Android banking Trojan family focused on SMS and notification interception, remote fraud enablement, and socially engineered delivery.

Capabilities

  • Credential Theft
  • Defense Evasion
  • Exfiltration
  • Post Exploitation

Observed infrastructure

Last seven days

First activity
Sep 3, 2026
Last activity
Sep 5, 2026
Feed role
Distribution
Host form
0 IP / 4 hostnames

Leading locations

  • RU2
  • US2

Leading providers

  • Amazon.com, Inc.2
  • "Domain names registrar REG.RU", Ltd1
  • Domain names registrar REG.RU, Ltd1

Infrastructure traits

  • Hosting 4
  • Anycast 2

MITRE ATT&CK

Mamont in ATT&CK

19 distinct techniques

Reporting

Research mentioning Mamont

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.