AndroidOS malware family
AndroidOS is a malware family tracked by MalwareAnalyzer by Cyble across 6 publicly analyzed samples. First seen 2026-07-31, most recently 2026-08-04.
Corpus statistics
- Publicly analyzed samples: 6
- First seen: 2026-07-31
- Last seen: 2026-08-04
- Verdicts: malicious 6
- File types: apk 6
Extracted command-and-control infrastructure
- https://bit.ly/3GfZoys - 1 sample
- https://publicsuffix.org/list/public_suffix_list.dat - 1 sample
- https://www.bouncycastle.org - 1 sample
- https://youtrack.jetbrains.com/issue/KT-46465 - 1 sample
Recent AndroidOS samples
- 2wvVwG9oCkNU.apk - malicious (2026-08-04)
- app.apk - malicious (2026-08-01)
- b7f8c6b76b8b1a0f99fbec5eb467983e8fd18f3ef496957bd8fb9c5bfca5e50b.apk - malicious (2026-07-31)
- 36ef3a11514f39f0143155711a4ca40ec546031a675a94c3b65dbae2c6d86e52.apk - malicious (2026-07-31)
- 4b8a2fdaad0f3e6e6325d3deef163526e470c9a88a23f73e491bd228f3548641.apk - malicious (2026-07-31)
- 25e6a6bac0859c785063eed88c04cfbb1c30613c9b549d846d43d1920db172e9.apk - malicious (2026-07-31)
Frequently asked about AndroidOS
- What is AndroidOS?
- AndroidOS is a malware family tracked by MalwareAnalyzer by Cyble across 6 publicly analyzed samples. First seen 2026-07-31, most recently 2026-08-04.
- How many AndroidOS samples have been analyzed?
- MalwareAnalyzer by Cyble holds 6 publicly analyzed samples attributed to AndroidOS, first seen 2026-07-31 and most recently 2026-08-04. This counts public submissions to this platform only, so it is a measure of what we have seen rather than of the family's total prevalence.
- What file types does AndroidOS use?
- AndroidOS samples in this corpus are distributed as apk (6).
- Does AndroidOS use command-and-control infrastructure?
- Yes. 4 distinct command-and-control indicators have been extracted from AndroidOS samples, either from static configuration or from traffic captured during sandbox detonation. The full list is published on the family page.
- Is AndroidOS malicious?
- 6 of 6 analyzed AndroidOS samples were scored malicious by the fused verdict, which combines multi-engine static scanning, YARA and hash reputation with behavior captured during real sandbox detonation. Each report lists every signal that contributed to its score.
Latest analyzed threats · ATT&CK coverage across the corpus · Threat trends