Executive Summary
MobileOrder is an Android trojan linked to the Scarlet Mimic actor that covertly installs on phones, harvests banking credentials, and exfiltrates data over encrypted channels. It poses a significant financial risk by enabling unauthorized transactions and can persist using stealthy background services. Security teams should detect anomalous outbound traffic and enforce app permission controls.
Enhanced Description
MobileOrder is a malicious Android trojan that has been attributed to the Scarlet Mimic threat actor. Although detailed technical resources are scarce, available documentation indicates the malware installs itself on compromised smartphones and operates silently in the background to harvest sensitive information and facilitate financial fraud. The application uses stealthy obfuscation and encryption to conceal network traffic and payload content. It typically reaches target devices through malicious app downloads or social‑engineering tactics such as phishing SMS messages that entice users to grant full permissions. Once installed, MobileOrder can capture banking credentials, intercept authentication tokens, harvest device identifiers, and exfiltrate data via encrypted HTTP(S) channels to externally controlled command‑and‑control (C2) servers. The impact on victims is primarily financial and privacy‑based: attackers may use the captured information to compromise bank accounts, trigger unauthorized transactions, or conduct further lateral movement within an enterprise's mobile ecosystem. The trojan’s persistence mechanisms can include creating background services that evade standard device management controls, making detection by conventional anti‑virus scanners more challenging. *Note:* These capabilities are inferred from threat intelligence reports and the association with Scarlet Mimic; direct analysis of binaries or network logs is lacking at present.
Key Capabilities
ATT&CK Techniques
Recommended Actions
Suggested Tags
Confidence Assessment
Confidence in the existence and basic description of MobileOrder is moderate, supported by secondary threat actor attribution (Scarlet Mimic). However, there is limited publicly available technical evidence—no detailed analysis of the code, distribution vector, or full capabilities. Key gaps include lack of firmware samples, precise C2 infrastructure details, and operational context.
MobileOrder is a Trojan intended to compromise Android mobile devices. It has been used by Scarlet Mimic. (Citation: Scarlet Mimic Jan 2016)