Skip to content

MoqHao

MoqHao, also known as Wroba, Shaoye, and XLoader for Android, is an Android malware family closely associated with the Roaming Mantis cybercrime operation.

Profile source: Mallory opens in a new tab

MoqHao

Family profile

MoqHao, also known as Wroba, Shaoye, and XLoader for Android, is an Android malware family closely associated with the Roaming Mantis cybercrime operation. It has been active for years in large-scale mobile campaigns that initially concentrated on East Asia, especially Japan and Korea, and later expanded across Europe, Africa, the Middle East, Oceania, and the Americas. The malware is primarily distributed through smishing campaigns that impersonate parcel-delivery or service notifications and lure victims into installing malicious Android applications, often disguised as browser or app updates.

MoqHao is best characterized as an Android remote access trojan with information-stealing and backdoor functionality, and some reporting also describes variants as banking trojans or mobile spyware. Once installed, it commonly requests SMS-related permissions, can read and send text messages, collect device and user information, and communicate with attacker-controlled infrastructure for tasking. Observed campaigns have used social-media profiles as dead-drop resolvers to publish encrypted command-and-control configuration, demonstrating an emphasis on resilience and operational flexibility. Technical analyses have also documented packed and dynamically loaded payloads, native-code-assisted loading, encrypted assets, hidden icons, and other anti-analysis or defense-evasion measures.

A notable operational feature of MoqHao is its ability to propagate through SMS messaging in a worm-like fashion by sending further lure messages from infected devices. Some variants have also been observed starting malicious activity automatically after installation, reducing the need for explicit user execution. Beyond handset compromise, newer samples have been reported attempting to identify vulnerable wireless routers, solve text-based CAPTCHA challenges through OCR services, brute-force administrative logins, and alter DNS settings to support downstream phishing or malware delivery.

Roaming Mantis has used MoqHao in financially motivated campaigns against mobile users worldwide. Delivery infrastructure has employed geofencing and device fingerprinting to selectively serve Android malware to Android users while redirecting iPhone users to credential-harvesting pages, indicating coordinated cross-platform fraud operations. Targeting has frequently used logistics and package-delivery themes, and campaigns have affected consumers at significant scale.

Capabilities

  • Brute Force
  • Credential Theft
  • Defense Evasion
  • Exfiltration
  • Persistence
  • Spoofing

Observed infrastructure

Last seven days

First activity
Sep 11, 2026
Last activity
Sep 11, 2026
Feed role
Distribution
Host form
0 IP / 1 hostnames

Leading locations

  • CA1

Leading providers

  • Netminders Server Hosting1

Infrastructure traits

  • Hosting 1

Samples

Recent associated samples

Reported operators

Threat actors

2 named in public reporting
Roaming Mantis

This blog post is part of an ongoing series of analysis on MoqHao (also referred to as Wroba and XLoader), a malware family commonly associated with Roaming Mantis. MoqHao is generally used to target Android users, often via an initial attack vector of phishing SMS messages (smishing).

Yanbian Gang

Ever received a text message alerting you to problems with the delivery of a package - even though you weren't waiting for one? Then you've already met Moqhao in person, also known as Shaoye or XLoader. Moqhao is something like the bestseller from the Roaming Mantis malware family, ready to build a backdoor into your smartphone's Android operating system.

MITRE ATT&CK

MoqHao in ATT&CK

28 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.