Roaming Mantis malware
Roaming Mantis is a long-running, financially motivated cybercriminal operation that targets mobile phone users. Active since 2018, it works mainly through SMS phishing, known as smishing: a text message pretending to come from a delivery company or a service provider carries a link, and what happens next depends on the phone. Android users are steered toward installing a malicious application disguised as a browser update, while iPhone users are sent to a page that imitates an Apple sign-in screen to harvest their credentials. The operation is assessed to be Chinese-speaking and has a history of targeting wealthy countries, moving from East Asia into Europe and beyond. It's an unusual entry in a security glossary, because its targets are individuals rather than corporate networks. It belongs here anyway, and this page explains why: an operation that intercepts text messages on a personal phone reaches directly into the authentication that many organizations still rely on.
Key takeaways
- Roaming Mantis targets phones, not corporate networks. Its route in is a text message to an individual, which puts it outside most enterprise monitoring.
- It adapts to the device. The same link delivers Android malware or an Apple credential-phishing page depending on the phone, and serves nothing at all outside the country being targeted.
- Roaming Mantis is the operation; MoqHao is the malware. The Android implant is also called Wroba and XLoader for Android, which is a frequent source of confusion.
- It intercepts SMS. That capability defeats one-time codes sent by text, which is the practical reason a consumer campaign matters to a security team.
- It has also hijacked routers. Compromising home Wi-Fi routers to redirect browsing toward fake update pages is a documented second route, independent of any text message.
Roaming Mantis and MoqHao, the operation and the malware
These names get used interchangeably and they shouldn't be. Roaming Mantis is the name for the operation and the group behind it. MoqHao is the Android malware it distributes, and that malware is also tracked as Wroba and as XLoader for Android. So a report about MoqHao is describing the implant, while a report about Roaming Mantis is describing the campaign that delivers it, along with the router hijacking and the Apple credential phishing that don't involve the Android malware at all.
The distinction matters when you're reading coverage to work out what you're exposed to. An iPhone user targeted by this operation never encounters MoqHao; they encounter a convincing fake sign-in page. Treating the two names as synonyms makes half the activity invisible.
How Roaming Mantis operates
The operation is built around a single link that behaves differently for every visitor, which is both an efficiency and an evasion measure.
- A text message with a plausible pretext. Most commonly a parcel delivery notification, occasionally an account or service alert. The pretext works because almost everyone is expecting a delivery, and because a text feels more immediate and more trustworthy than an email.
- Checks before anything is served. The server examines where the visitor is connecting from and what device they're using, then decides what to send. Visitors outside the country being targeted get nothing at all, which frustrates analysis as well as focusing the campaign.
- Android: a fake browser update. Users in scope are prompted to install an application presented as a browser update. The application then requests permission to read and send text messages, and it imitates a well-known browser to make that request look reasonable.
- iPhone: a fake sign-in page. Users on iOS are sent instead to a page imitating an Apple account login, in the language of the country being targeted, to collect credentials.
- Instructions hidden in a legitimate service. Rather than hard-coding a server address, the malware retrieves it from the profile page of an account on a public image-hosting service, where it's stored encrypted. This makes the malware harder to disrupt, because the address can be changed without updating the app.
- Router hijacking as an alternative route. Separately from the text messages, the operation has compromised home Wi-Fi routers and altered their name resolution settings, so that ordinary browsing on any device using that network is redirected to fake pages.
Once installed, the Android malware can also send text messages of its own, which means an infected phone becomes a distribution point that texts the owner's contacts. The messages then arrive from a real, known number.
What Roaming Mantis steals
Reported collection is broad, and it's worth reading the list with authentication in mind rather than only privacy.
Sekoia's research on Roaming Mantis
Sekoia's Threat Detection & Research (TDR) team documented a Roaming Mantis campaign against France in 2022, and the investigation started in an unusually direct way: a Sekoia analyst received one of the malicious text messages personally. Following that message led the team to an active campaign running across the country.
The technical findings set out how selective the delivery was. The server checked the visitor's apparent location and device before responding: nothing for visitors outside France, the Android application for Android users in France, and the fake Apple sign-in page for iPhone users in France. TDR also documented how the malware located its command server, retrieving an encrypted address from the profile of an account on a public image-hosting service, a technique that lets operators move infrastructure without touching the installed app.
On scale, the team's assessment was that the campaign likely resulted in around seventy thousand compromised Android devices in France, based in part on observing more than ninety thousand distinct addresses contacting the server distributing the malware. Two things are worth noting about those numbers. They're an assessment rather than a count, and TDR presented them as such. And they describe consumer devices, which is a scale of compromise that rarely appears in enterprise incident statistics precisely because nobody is monitoring the affected devices.
TDR's closing assessment is the part most relevant to a security team. It judged that the volume of sensitive data collected could be used for extortion, sold on to other criminal groups, or exploited in big-game operations against organizations. That connects a consumer smishing campaign to the enterprise threat landscape through the criminal economy rather than through any direct corporate intrusion.
Why a consumer smishing campaign concerns organizations
Three mechanisms connect this to corporate risk, and none requires the operation to target a company directly.
- One-time codes sent by text are readable. Malware that can read incoming messages can read an authentication code. Any system protected by SMS-delivered passcodes offers no protection against someone holding those messages, and that includes corporate systems accessed from a personal phone.
- Personal devices reach corporate resources. Where staff use their own phones for work email, chat, or cloud applications, a compromise of that phone is an exposure of the organization, whether or not the device is managed.
- The stolen data enters a market. As Sekoia's own assessment notes, credentials and personal information collected at this scale can be sold onward, and the buyers include groups that specialize in intrusions against organizations.
How to defend against Roaming Mantis
Defence splits between what an organization can control and what it can only advise:
- Move off SMS-based authentication. This is the highest-value action. Replace text-message codes with an authenticator application or, better, phishing-resistant hardware or platform authenticators. SMS interception is a documented capability of this malware, not a theoretical risk.
- Block installation from outside official app stores. On managed Android devices, preventing sideloading removes the delivery mechanism entirely. On personal devices, this is advice rather than a control, which is an argument for the first point.
- Tell people the pretext, not just the principle. Staff should know that unexpected delivery notifications by text are a live technique, and that a message from a known contact's number can still be malicious because infected phones text their own contact lists.
- Address home routers in guidance. Advise updating router firmware and replacing default administrator passwords, since router hijacking is a documented route that bypasses the text message entirely.
- Treat a suspected mobile compromise as a credential incident. If a work-linked account was accessible from an affected phone, reset the credentials and revoke active sessions rather than assuming the malware simply needs removing.
Why this campaign is an argument against SMS authentication
Roaming Mantis is easy to file under consumer fraud. Parcel delivery texts, fake browser updates, stolen banking details: none of it looks like an enterprise threat, and none of it will appear in a corporate incident report. But one capability changes its category. This malware asks for permission to read text messages, and it gets it, because the request arrives from something imitating a browser and looks routine. From that point, every one-time passcode delivered to that phone is readable by someone else.
Organizations that still send authentication codes by text are relying on the secrecy of a channel this operation has been reading at scale since 2018. That's not a hypothetical weakness in a protocol; it's an observed capability in malware installed on tens of thousands of phones in a single country in a single campaign, as Sekoia's own research found. Sekoia is a European cybersecurity vendor, and detection on its SOC platform is built on correlated behaviour across identity, endpoint, network and cloud signals, mapped to the MITRE ATT&CK framework and informed by cyber threat intelligence produced by an in-house TDR team that has tracked this operation directly. What that layer can surface is the consequence: an authentication succeeding from somewhere implausible, a session appearing where it shouldn't, an account behaving unlike itself. The compromise of the phone is invisible to the organization. The use of what was stolen from it is not.
The practical conclusion is narrow and worth acting on. You cannot defend the personal phones of your staff, and you shouldn't build a strategy that depends on doing so. What you can do is stop treating a text message as a second factor, and make sure the identity signals that follow a stolen code are being watched.