Tox
1 totalFA21E360945F602504728A05A39758C38B6A5B5DA1969717AF05838D14FDCD3DE17455833F11
INSOMNIA is an iOS surveillance malware family associated with mobile espionage activity.
Profile source: Mallory opens in a new tabINSOMNIA
INSOMNIA is an iOS surveillance malware family associated with mobile espionage activity. It is designed to profile compromised devices and collect a broad range of user and application data, including contacts, call history, SMS messages, iMessages, installed non-Apple applications, device identifiers, storage information, and application database content such as data from Gmail, Hangouts, photos, and third-party app containers. Its behavior indicates a strong emphasis on intelligence collection from local device storage and communications artifacts.
The malware communicates with command-and-control infrastructure over HTTPS, allowing it to blend with normal encrypted application traffic while supporting remote tasking and data exfiltration. Reported collection of call history and certain protected local data on iOS suggests operation in a post-compromise context where elevated privileges may be available or where the implant otherwise has access beyond standard app sandbox restrictions. INSOMNIA fits the profile of mobile spyware used for persistent surveillance and theft of sensitive personal and application data from Apple mobile devices.
FA21E360945F602504728A05A39758C38B6A5B5DA1969717AF05838D14FDCD3DE17455833F11Reported operators
INSOMNIA communicates with the C2 server using HTTPS requests.
"...contained malicious javascript code that resembled previously reported exploits, which installed iOS malware known as INSOMNIA on people’s devices once they were compromised."
MITRE ATT&CK
Reporting
Researchers identified an Android malware app named iMobile that impersonates India’s Income Tax Department and targets Indian taxpayers through phishing, harvesting sensitive data including PAN, Aadhaar, bank account information, debit card details, and internet banking credentials. The app also seeks extensive dangerous permissions and attempts to set itself as the device’s default SMS application, giving it the ability to read, receive, and send text messages while monitoring phone state and usage data. Analysis showed the stolen banking and internet-banking information was uploaded to the command-and-control endpoint jsig.quicksytes[.]com/MC/NN180521/mc.php, and the sample used string deobfuscation and hardcoded artifacts including an Indian mobile number. The campaign reflects a broader mobile threat pattern documented in MITRE ATT&CK T1636.004, where malicious apps abuse SMS access to intercept messages, including one-time passcodes and transaction alerts, to support credential theft, financial fraud, and account takeover.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.