Threat ResearchAndroid banking trojan / SMS stealer2024Analyzed 2026-09-08

Mamont: recovered C2 indicators & analysis

An Android banking trojan and SMS stealer that targets Russian-speaking users, spread through Telegram and messenger phishing while posing as parcel-tracking, video, or brand-name apps, and used to intercept SMS and notifications and drain accounts through SMS banking. · also known as Trojan-Banker.AndroidOS.Mamont (Kaspersky), Trojan:AndroidOS/Mamont (Microsoft), Mamont banker

What Mamont is

Mamont is an Android banking trojan that also functions as an SMS and notification stealer. It was first reported in 2024 and predominantly targets Russian-speaking users, especially in Russia. The name is Russian for 'mammoth' and is criminal slang for a scam victim; Kaspersky detects it as Trojan-Banker.AndroidOS.Mamont.

Distribution relies on social engineering and phishing through Telegram and other messengers: fake online stores advertising cheap or bulk-priced goods route victims into a Telegram chat and push a malicious 'parcel-tracking' APK, alongside video-file lures (for example filenames asking 'Is this you in the video?') and earlier variants impersonating Google Chrome.

Its core capabilities center on SMS. It intercepts and forwards incoming and recent historical text messages, parses them for banking-related keywords and monetary amounts, and can send SMS and USSD requests to move funds via SMS-banking services.

Beyond SMS, it hijacks push notifications, harvests card and credential data through fake in-app input windows, collects device information such as installed applications, phone number, and SIM/operator details, can upload photos from the device, and can hide or change its app icon to evade detection.

Command-and-control varies by variant and has included attacker-controlled Telegram bots or channels, JSON-formatted commands over a WebSocket server, and direct HTTP connections to attacker-controlled IP addresses.

Kaspersky reported Mamont as the dominant Android banking trojan family through 2025 and into 2026, accounting for roughly 73.5% of banking-trojan detections in Q1 2026 and driven by numerous actively developed variants; in March 2025 Russian authorities arrested three suspects in the Saratov region linked to more than 300 cybercrime incidents.

Capabilities

Known C2 / channel types: Telegram channels and chats (delivery and command-and-control), Other messengers and phishing links (e.g. WhatsApp), Fake online / wholesale storefronts, APK sideloading disguised as Chrome, parcel trackers, video files, or dating apps, WebSocket C2 server, Direct HTTP to attacker-controlled IP address.

MITRE ATT&CK (Mobile)

Techniques commonly associated with Mamont:

IDTechnique
T1660Phishing
T1655.001Masquerading: Match Legitimate Name or Location
T1628.001Hide Artifacts: Suppress Application Icon
T1636.004Protected User Data: SMS Messages
T1582SMS Control
T1517Access Notifications
T1417.002Input Capture: GUI Input Capture
T1426System Information Discovery
T1418Software Discovery
T1437.001Application Layer Protocol: Web Protocols
T1481.002Web Service: Bidirectional Communication

What Privara Unmask recovered

One C2 endpoint with an explicit port (194.41.113.39:8081) was recovered from the APK's appended config and contributed to ThreatFox. Four further C2 IP addresses were recovered from the encrypted config but are reported as held — they carried no observed port (the sample never reached live infrastructure), and submitting a guessed port would lower the quality of the indicator. The analysis ran on a de-emulated Android 17 device that the sample could not fingerprint as virtual, so it behaved as it would on a real handset.

SHA-256 bd8d876a63c55a252a600f565c9ccc0f9d2375a0a341b84f5821b07d85f111de
Source MalwareBazaar (abuse.ch)
Community contribution. Published to ThreatFox (novel) on 2026-09-04 as unknown_stealer (Mamont has no Malpedia entry), ~50% confidence (config-extracted).

Indicators of compromise (IOCs)

IndicatorTypeRoleConfidenceStatus
194.41.113.39:8081
recovered from the APK's appended config (raw-bytes extractor)
ip:portC2mediumoffline

Recovered but withheld from the feed (precision over volume):

Status note. The indicators above were unresponsive (offline / sinkholed) at analysis time and are published as historical threat intelligence. Co-observed benign and environmental artifacts have been removed rather than reported as C2.

External references

Methodology & honest limits

This sample was obtained from MalwareBazaar and detonated in a controlled, isolated environment. C2 identity was recovered from the executing sample and its configuration. We report only what the analysis established: an offline sample yields a C2 identity, not a live beacon, and we say so. Nothing here is inferred beyond the evidence.

Analyze your own Android samples like this

Privara Unmask detonates arm64 samples on a de-emulated Android 17 device that anti-analysis code can't fingerprint — recovering C2, config and IOCs automatically, with a clean rollback per sample.

See the sandbox → Request a demo