Mamont: recovered C2 indicators & analysis
An Android banking trojan and SMS stealer that targets Russian-speaking users, spread through Telegram and messenger phishing while posing as parcel-tracking, video, or brand-name apps, and used to intercept SMS and notifications and drain accounts through SMS banking. · also known as Trojan-Banker.AndroidOS.Mamont (Kaspersky), Trojan:AndroidOS/Mamont (Microsoft), Mamont banker
What Mamont is
Mamont is an Android banking trojan that also functions as an SMS and notification stealer. It was first reported in 2024 and predominantly targets Russian-speaking users, especially in Russia. The name is Russian for 'mammoth' and is criminal slang for a scam victim; Kaspersky detects it as Trojan-Banker.AndroidOS.Mamont.
Distribution relies on social engineering and phishing through Telegram and other messengers: fake online stores advertising cheap or bulk-priced goods route victims into a Telegram chat and push a malicious 'parcel-tracking' APK, alongside video-file lures (for example filenames asking 'Is this you in the video?') and earlier variants impersonating Google Chrome.
Its core capabilities center on SMS. It intercepts and forwards incoming and recent historical text messages, parses them for banking-related keywords and monetary amounts, and can send SMS and USSD requests to move funds via SMS-banking services.
Beyond SMS, it hijacks push notifications, harvests card and credential data through fake in-app input windows, collects device information such as installed applications, phone number, and SIM/operator details, can upload photos from the device, and can hide or change its app icon to evade detection.
Command-and-control varies by variant and has included attacker-controlled Telegram bots or channels, JSON-formatted commands over a WebSocket server, and direct HTTP connections to attacker-controlled IP addresses.
Kaspersky reported Mamont as the dominant Android banking trojan family through 2025 and into 2026, accounting for roughly 73.5% of banking-trojan detections in Q1 2026 and driven by numerous actively developed variants; in March 2025 Russian authorities arrested three suspects in the Saratov region linked to more than 300 cybercrime incidents.
Capabilities
- Intercepts and forwards incoming SMS messages, including recent message history
- Scans SMS for banking keywords, monetary amounts, and one-time/2FA codes
- Sends SMS and USSD requests to perform SMS-banking fund transfers
- Hijacks and reads push notifications
- Steals card and credential data through fake input windows and forms
- Collects device information: installed apps, phone number, SIM/operator details
- Uploads photos from the infected device
- Hides or changes the app icon to evade detection
- Masquerades as legitimate apps (Google Chrome, parcel trackers, dating apps)
- Communicates with C2 via Telegram, a WebSocket server (JSON commands), or direct HTTP to an attacker IP
Known C2 / channel types: Telegram channels and chats (delivery and command-and-control), Other messengers and phishing links (e.g. WhatsApp), Fake online / wholesale storefronts, APK sideloading disguised as Chrome, parcel trackers, video files, or dating apps, WebSocket C2 server, Direct HTTP to attacker-controlled IP address.
MITRE ATT&CK (Mobile)
Techniques commonly associated with Mamont:
| ID | Technique |
|---|---|
| T1660 | Phishing |
| T1655.001 | Masquerading: Match Legitimate Name or Location |
| T1628.001 | Hide Artifacts: Suppress Application Icon |
| T1636.004 | Protected User Data: SMS Messages |
| T1582 | SMS Control |
| T1517 | Access Notifications |
| T1417.002 | Input Capture: GUI Input Capture |
| T1426 | System Information Discovery |
| T1418 | Software Discovery |
| T1437.001 | Application Layer Protocol: Web Protocols |
| T1481.002 | Web Service: Bidirectional Communication |
What Privara Unmask recovered
One C2 endpoint with an explicit port (194.41.113.39:8081) was recovered from the APK's appended config and contributed to ThreatFox. Four further C2 IP addresses were recovered from the encrypted config but are reported as held — they carried no observed port (the sample never reached live infrastructure), and submitting a guessed port would lower the quality of the indicator. The analysis ran on a de-emulated Android 17 device that the sample could not fingerprint as virtual, so it behaved as it would on a real handset.
Source MalwareBazaar (abuse.ch)
Indicators of compromise (IOCs)
| Indicator | Type | Role | Confidence | Status |
|---|---|---|---|---|
| 194.41.113.39:8081 recovered from the APK's appended config (raw-bytes extractor) | ip:port | C2 | medium | offline |
Recovered but withheld from the feed (precision over volume):
- 95.215.108.110 — bare IP, no observed port (dead RU infra)
- 2.59.161.117 — bare IP, no observed port (dead RU infra)
- 185.214.74.200 — bare IP, no observed port (dead RU infra)
- 147.45.219.172 — bare IP, no observed port (dead RU infra)
External references
- The Mamont banker masquerades as an app for tracking bulk purchasesKaspersky (Securelist)
- Q1 2026 Android threat landscapeKaspersky (Securelist)
- Mamont: An Android banking Trojan posing as ChromeG DATA
- Dissecting Android Malware - Post 1: Mamont Banking TrojanNCC Group
- Russia arrests three for allegedly creating Mamont malware, tied to over 300 cybercrimesThe Record (Recorded Future News)
- Mamont banker under the guise of a tracking appKaspersky
Methodology & honest limits
This sample was obtained from MalwareBazaar and detonated in a controlled, isolated environment. C2 identity was recovered from the executing sample and its configuration. We report only what the analysis established: an offline sample yields a C2 identity, not a live beacon, and we say so. Nothing here is inferred beyond the evidence.
Analyze your own Android samples like this
Privara Unmask detonates arm64 samples on a de-emulated Android 17 device that anti-analysis code can't fingerprint — recovering C2, config and IOCs automatically, with a clean rollback per sample.
See the sandbox → Request a demo