Skip to main content

Black Hat Arsenal Black Hat Arsenal HITB defcon
build status codecov license python version PyPi Download
Twitter

Malware Family Analysis Report Showcase

Family Summary Signature Behaviors Report
DroidKungFu Privilege escalation with C2 control. 1. Gain unlimited access to a device.
2. Install/Uninstall additional apps.
3. Forward confidential data.
View
GoldDream SMS/call log exfiltration with remote C2 commands. 1. Monitor SMS messages and phone calls.
2. Upload SMS messages and phone calls to remote servers.
View
SpyNote Credential theft and device surveillance via RAT. 1. Take screenshots.
2. Simulate user gestures.
3. Log user input.
4. Communicate with C2 servers.
View
DawDropper Dropper that installs banking trojans for financial theft. 1. Download APKs from remote servers.
2. Install additional APKs.
View
SLocker Android ransomware locking/encrypting devices. 1. Lock the device with an overlay screen. View
PhantomCard NFC relay–based financial fraud. 1. Communicate with C2 servers.
2. Read the payment data of NFC cards.
3. Captures PINs of NFC cards through deceptive screens.
View
ToxicPanda Banking trojan enabling on-device fraud. 1. Abuse Accessibility.
2. Remote device control.
3. Intercept OTP.
View
Hydra Banking trojan using overlay attacks. 1. Overlay credential theft.
2. Accessibility abuse.
3. Steal OTP/cookies.
View
SharkBot Banking trojan targeting financial credentials and transactions. 1. Abuse Accessibility services.
2. Perform overlay attacks to steal credentials.
3. Intercept SMS messages (OTP).
View
Antidot Banking trojan disguised as legitimate updates for financial data theft. 1. Intercept SMS messages (OTP).
2. Log user input (keylogging).
3. Enable remote control via C2.
View
Arsink Banking trojan focusing on credential and financial data exfiltration. 1. Steal sensitive data from device.
2. Intercept SMS messages (OTP).
View
TrickMo Banking trojan using overlay attacks and accessibility abuse for credential theft. 1. Overlay attacks to steal banking credentials.
2. Intercept SMS for 2FA bypass.
3. Screen recording and accessibility abuse.
4. Dynamic payload loading via reflection.
View
Anubis Banking trojan with RAT capabilities. 1. Overlay credential theft.
2. Keylogging.
3. Intercept SMS (OTP).
4. Remote control via C2.
View
GodFather Banking trojan targeting financial credentials through overlay and accessibility abuse. 1. Perform overlay attacks to steal credentials.
2. Abuse Accessibility services.
3. Intercept SMS messages (OTP).
4. Steal banking credentials and sensitive data.
View
TangleBot SMS-based Android malware stealing personal and financial data. 1. Spread through SMS phishing links.
2. Control device interactions and overlay screens.
3. Access SMS, contacts, call logs, camera, and microphone.
4. Steal account and financial information.
View
BRATA Banking trojan with remote control and anti-analysis capabilities. 1. Perform overlay attacks to steal banking credentials.
2. Abuse Accessibility services for device control.
3. Intercept SMS messages (OTP).
4. Execute factory reset or device wipe commands.
View
Cerberus Banking trojan targeting financial credentials through overlay and device control. 1. Perform overlay attacks to steal credentials.
2. Abuse Accessibility services.
3. Log user input (keylogging).
4. Enable remote control via C2.
View
SuperCardX NFC relay malware enabling contactless payment fraud. 1. Read NFC payment card data.
2. Relay NFC transactions to attacker-controlled devices.
3. Communicate with C2 servers.
4. Facilitate unauthorized contactless payments.
View
NGate NFC-based malware enabling relay attacks and payment fraud. 1. Read NFC payment card data.
2. Relay NFC communications to attacker-controlled devices.
3. Communicate with C2 servers.
4. Facilitate unauthorized contactless payments.
View
AhRat Android RAT capable of surveillance and data theft. 1. Record audio from the device.
2. Steal files and sensitive data.
3. Remote access via C2.
4. Execute remote commands.
View
AndroRat Android remote access trojan for device surveillance. 1. Record audio and capture video.
2. Track device location.
3. Steal files and device information.
4. Execute remote commands.
View
Sova Android banking trojan distributed as trojanised carrier apps for credential theft and SMS fraud. 1. Read device identifiers via the C2 ping-response handler.
2. Inject outbound SMS on operator command.
3. Place phone calls without user consent.
View
EventBot Banking trojan and infostealer targeting 200+ financial apps. 1. Enumerate installed applications to pick targets.
2. Intercept incoming SMS via a broadcast receiver.
3. Exfiltrate SMS bodies over HTTP to defeat 2FA.
View
Skygofree Android spyware designed for surveillance and sensitive data collection. 1. Capture audio.
2. Access stored application data.
3. Download new code at runtime.
4. Capture video.
View

Quick Start

Step 1. Install via PyPi

Install the latest version of Quark Engine:

$ pip3 install -U quark-engine

Step 2. Download Latest Rules

Fetch the latest rule database:

$ freshquark

Step 3. Run Summary Report

Analyze an APK with the downloaded rules and generate a summary report:

$ quark -a <apk_file> -s

Step 4. View Results

Example output: Screenshot-2025-11-25-22-36-54

Quark-Engine Skills

Quark-Engine also ships two Claude Code skills:

  • /quark:analysis — analyze an APK with Quark-Engine
  • /quark:rule-gen — generate a Quark rule from decompiled code

To install, run these commands inside Claude Code after installing Quark-Engine:

/plugin marketplace add ev-flow/quark-engine
/plugin install quark@quark-engine

The skills then should appear.

Acknowledgments

The Honeynet Project

Honeynet.org logo

Google Summer Of Code

Quark-Engine has been participating in the GSoC under the Honeynet Project!

Stay tuned for the upcoming GSoC! Join the Honeynet Slack chat for more info.

Core Values of Quark Engine Team

  • We love battle fields. We embrace uncertainties. We challenge impossibles. We rethink everything. We change the way people think. And the most important of all, we benefit ourselves by benefit others first.

Release files for quark-engine 26.9.1

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for quark-engine 26.9.1
File Size Uploaded
quark_engine-26.9.1.tar.gz 120.9 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for quark-engine 26.9.1
File Interpreter ABI Platform
quark_engine-26.9.1-py3-none-any.whl Python 3 none any Details

Total release size: 262.0 kB

Release files / quark_engine-26.9.1.tar.gz

Download URL quark_engine-26.9.1.tar.gz
Size 120.9 kB
Tags Source
SHA-256 checksum
How to use checksums
a00dace5c3547995301d5d326b3e8e28cb4a8d84f3ed1350c63402c006b6ec95
BLAKE2b-256 checksum
How to use checksums
5198b7f848481aa3bf7d1ea108a3f226822823e94712a4ca5c87689a5606bd40
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.14.7

Release files / quark_engine-26.9.1-py3-none-any.whl

Download URL quark_engine-26.9.1-py3-none-any.whl
Size 141.1 kB
Tags Python 3
SHA-256 checksum
How to use checksums
0e97a2b22aa5e256e82888177e889324c178682ba721bfc4c9c45b6f317c50c4
BLAKE2b-256 checksum
How to use checksums
e7c338f3831f40b18742fab7a92c299b12366103858acfda9c112d2d5d1c514f
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.14.7

Release history Release notifications | RSS feed

This release

26.9.1 This release

2 release files

26.4.1

2 release files

23.9.1

2 release files

23.8.1

2 release files

23.7.1

2 release files

23.6.1

2 release files

23.5.1

2 release files

23.4.1

2 release files

23.3.1

2 release files

23.2.1

2 release files

22.9.1

2 release files

22.7.1

2 release files

22.6.1

2 release files

22.5.1

2 release files

22.4.1

2 release files

22.3.1

2 release files

22.2.1

2 release files

21.8.1

2 release files

21.7.2

2 release files

21.7.1

2 release files

21.6.3

2 release files

21.5.1

2 release files

21.3.4

2 release files

21.3.3

2 release files

21.2.2

2 release files

21.1.6

2 release files

21.1.5

2 release files

21.1.4

2 release files

21.1.3

2 release files

21.1.2

2 release files

20.12

2 release files

20.11

2 release files

20.8

2 release files

20.4

3 release files

20.1

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page