Last seven days
- First activity
- Sep 11, 2026
- Last activity
- Sep 11, 2026
- Feed role
- Distribution
- Host form
- 0 IP / 1 hostnames
MoqHao, also known as Wroba, Shaoye, and XLoader for Android, is an Android malware family closely associated with the Roaming Mantis cybercrime operation.
Profile source: Mallory opens in a new tabMoqHao
MoqHao, also known as Wroba, Shaoye, and XLoader for Android, is an Android malware family closely associated with the Roaming Mantis cybercrime operation. It has been active for years in large-scale mobile campaigns that initially concentrated on East Asia, especially Japan and Korea, and later expanded across Europe, Africa, the Middle East, Oceania, and the Americas. The malware is primarily distributed through smishing campaigns that impersonate parcel-delivery or service notifications and lure victims into installing malicious Android applications, often disguised as browser or app updates.
MoqHao is best characterized as an Android remote access trojan with information-stealing and backdoor functionality, and some reporting also describes variants as banking trojans or mobile spyware. Once installed, it commonly requests SMS-related permissions, can read and send text messages, collect device and user information, and communicate with attacker-controlled infrastructure for tasking. Observed campaigns have used social-media profiles as dead-drop resolvers to publish encrypted command-and-control configuration, demonstrating an emphasis on resilience and operational flexibility. Technical analyses have also documented packed and dynamically loaded payloads, native-code-assisted loading, encrypted assets, hidden icons, and other anti-analysis or defense-evasion measures.
A notable operational feature of MoqHao is its ability to propagate through SMS messaging in a worm-like fashion by sending further lure messages from infected devices. Some variants have also been observed starting malicious activity automatically after installation, reducing the need for explicit user execution. Beyond handset compromise, newer samples have been reported attempting to identify vulnerable wireless routers, solve text-based CAPTCHA challenges through OCR services, brute-force administrative logins, and alter DNS settings to support downstream phishing or malware delivery.
Roaming Mantis has used MoqHao in financially motivated campaigns against mobile users worldwide. Delivery infrastructure has employed geofencing and device fingerprinting to selectively serve Android malware to Android users while redirecting iPhone users to credential-harvesting pages, indicating coordinated cross-platform fraud operations. Targeting has frequently used logistics and package-delivery themes, and campaigns have affected consumers at significant scale.
Samples
Reported operators
This blog post is part of an ongoing series of analysis on MoqHao (also referred to as Wroba and XLoader), a malware family commonly associated with Roaming Mantis. MoqHao is generally used to target Android users, often via an initial attack vector of phishing SMS messages (smishing).
Ever received a text message alerting you to problems with the delivery of a package - even though you weren't waiting for one? Then you've already met Moqhao in person, also known as Shaoye or XLoader. Moqhao is something like the bestseller from the Roaming Mantis malware family, ready to build a backdoor into your smartphone's Android operating system.
MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.