Skip to main content

Black Hat Arsenal Black Hat Arsenal HITB defcon
build status codecov license python version PyPi Download
Twitter

Malware Family Analysis Report Showcase

Family Summary Signature Behaviors Report
DroidKungFu Privilege escalation with C2 control. 1. Gain unlimited access to a device.
2. Install/Uninstall additional apps.
3. Forward confidential data.
View
GoldDream SMS/call log exfiltration with remote C2 commands. 1. Monitor SMS messages and phone calls.
2. Upload SMS messages and phone calls to remote servers.
View
SpyNote Credential theft and device surveillance via RAT. 1. Take screenshots.
2. Simulate user gestures.
3. Log user input.
4. Communicate with C2 servers.
View
DawDropper Dropper that installs banking trojans for financial theft. 1. Download APKs from remote servers.
2. Install additional APKs.
View
SLocker Android ransomware locking/encrypting devices. 1. Lock the device with an overlay screen. View
PhantomCard NFC relay–based financial fraud. 1. Communicate with C2 servers.
2. Read the payment data of NFC cards.
3. Captures PINs of NFC cards through deceptive screens.
View
ToxicPanda Banking trojan enabling on-device fraud. 1. Abuse Accessibility.
2. Remote device control.
3. Intercept OTP.
View
Hydra Banking trojan using overlay attacks. 1. Overlay credential theft.
2. Accessibility abuse.
3. Steal OTP/cookies.
View
SharkBot Banking trojan targeting financial credentials and transactions. 1. Abuse Accessibility services.
2. Perform overlay attacks to steal credentials.
3. Intercept SMS messages (OTP).
View
Antidot Banking trojan disguised as legitimate updates for financial data theft. 1. Intercept SMS messages (OTP).
2. Log user input (keylogging).
3. Enable remote control via C2.
View
Arsink Banking trojan focusing on credential and financial data exfiltration. 1. Steal sensitive data from device.
2. Intercept SMS messages (OTP).
View
TrickMo Banking trojan using overlay attacks and accessibility abuse for credential theft. 1. Overlay attacks to steal banking credentials.
2. Intercept SMS for 2FA bypass.
3. Screen recording and accessibility abuse.
4. Dynamic payload loading via reflection.
View
Anubis Banking trojan with RAT capabilities. 1. Overlay credential theft.
2. Keylogging.
3. Intercept SMS (OTP).
4. Remote control via C2.
View
GodFather Banking trojan targeting financial credentials through overlay and accessibility abuse. 1. Perform overlay attacks to steal credentials.
2. Abuse Accessibility services.
3. Intercept SMS messages (OTP).
4. Steal banking credentials and sensitive data.
View
TangleBot SMS-based Android malware stealing personal and financial data. 1. Spread through SMS phishing links.
2. Control device interactions and overlay screens.
3. Access SMS, contacts, call logs, camera, and microphone.
4. Steal account and financial information.
View
BRATA Banking trojan with remote control and anti-analysis capabilities. 1. Perform overlay attacks to steal banking credentials.
2. Abuse Accessibility services for device control.
3. Intercept SMS messages (OTP).
4. Execute factory reset or device wipe commands.
View
Cerberus Banking trojan targeting financial credentials through overlay and device control. 1. Perform overlay attacks to steal credentials.
2. Abuse Accessibility services.
3. Log user input (keylogging).
4. Enable remote control via C2.
View
SuperCardX NFC relay malware enabling contactless payment fraud. 1. Read NFC payment card data.
2. Relay NFC transactions to attacker-controlled devices.
3. Communicate with C2 servers.
4. Facilitate unauthorized contactless payments.
View
NGate NFC-based malware enabling relay attacks and payment fraud. 1. Read NFC payment card data.
2. Relay NFC communications to attacker-controlled devices.
3. Communicate with C2 servers.
4. Facilitate unauthorized contactless payments.
View
AhRat Android RAT capable of surveillance and data theft. 1. Record audio from the device.
2. Steal files and sensitive data.
3. Remote access via C2.
4. Execute remote commands.
View
AndroRat Android remote access trojan for device surveillance. 1. Record audio and capture video.
2. Track device location.
3. Steal files and device information.
4. Execute remote commands.
View
Sova Android banking trojan distributed as trojanised carrier apps for credential theft and SMS fraud. 1. Read device identifiers via the C2 ping-response handler.
2. Inject outbound SMS on operator command.
3. Place phone calls without user consent.
View

Quick Start

Step 1. Install via PyPi

Install the latest version of Quark Engine:

$ pip3 install -U quark-engine

Step 2. Download Latest Rules

Fetch the latest rule database:

$ freshquark

Step 3. Run Summary Report

Analyze an APK with the downloaded rules and generate a summary report:

$ quark -a <apk_file> -s

Step 4. View Results

Example output: Screenshot-2025-11-25-22-36-54

Quark-Engine Skills

Quark-Engine also ships two Claude Code skills:

  • /quark:analysis — analyze an APK with Quark-Engine
  • /quark:rule-gen — generate a Quark rule from decompiled code

To install, run these commands inside Claude Code after installing Quark-Engine:

/plugin marketplace add ev-flow/quark-engine
/plugin install quark@quark-engine

The skills then should appear.

Acknowledgments

The Honeynet Project

Honeynet.org logo

Google Summer Of Code

Quark-Engine has been participating in the GSoC under the Honeynet Project!

Stay tuned for the upcoming GSoC! Join the Honeynet Slack chat for more info.

Core Values of Quark Engine Team

  • We love battle fields. We embrace uncertainties. We challenge impossibles. We rethink everything. We change the way people think. And the most important of all, we benefit ourselves by benefit others first.

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

quark_engine-26.8.1.tar.gz (117.5 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

quark_engine-26.8.1-py3-none-any.whl (138.5 kB view details)

Uploaded Python 3

File details

Details for the file quark_engine-26.8.1.tar.gz.

File metadata

  • Download URL: quark_engine-26.8.1.tar.gz
  • Upload date:
  • Size: 117.5 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/7.0.0 CPython/3.14.6

File hashes

Hashes for quark_engine-26.8.1.tar.gz
Algorithm Hash digest
SHA256 b83495a14d40f3001ead5e9de0fd8192c0a44c22779c8dc39d58b8b1e6a579f7
MD5 688703c61c7bbd85680043094c0624cf
BLAKE2b-256 d35e683f51c70e407e2f9d79a3c7181f2f7a30daa5342ccaf389d92dc6cfca5a

See more details on using hashes here.

File details

Details for the file quark_engine-26.8.1-py3-none-any.whl.

File metadata

  • Download URL: quark_engine-26.8.1-py3-none-any.whl
  • Upload date:
  • Size: 138.5 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/7.0.0 CPython/3.14.6

File hashes

Hashes for quark_engine-26.8.1-py3-none-any.whl
Algorithm Hash digest
SHA256 22232065d075d3e71476ff9e0bcc3aac29a09a73465f527af2b8fcca7445e767
MD5 1a3721bd3005980c2df95821386f8ded
BLAKE2b-256 2c16f683b0842f0b0635ca5164e0e3771dd26aac4265fdcb6f7c886823887d85

See more details on using hashes here.

Release history Release notifications | RSS feed

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page