Threat Group Cards: A Threat Actor Encyclopedia Archived: 2026-04-06 03:13:50 UTC Home > List all groups > List all tools > List all groups using tool Roaming Mantis Tool: Roaming Mantis Names Roaming Mantis MoqHao XLoader Wroba Category Malware Type Banking trojan, Info stealer, Miner Description (Kaspersky) The Roaming Mantis mobile banking trojan is roaming further afield than it ever has before. Recent analysis shows that the malware has rapidly evolved just in the past month. It’s now targeting Europe and the Middle East in addition to Asian countries. According to researchers, it’s following the cyber-zeitgeist by expanding its capabilities to include cryptomining (and iOS phishing). Roaming Mantis is a mostly-mobile malware which this year has been spreading via DNS hijacking. Potential victims are typically redirected to a malicious webpage that distributes a trojanized application that pretends to be either Facebook or Chrome. Once installed manually by users, a trojan banker will execute. Information https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=aa243282-d977-4d61-81a2-b81c17ac47f3 Page 1 of 2 MITRE ATT&CK Malpedia AlienVault OTX Last change to this tool card: 06 March 2024 Download this tool card in JSON format All groups using tool Roaming Mantis Changed Name Country Observed Other groups Roaming Mantis [Unknown] 2017-Jul 2022 1 group listed (0 APT, 1 other, 0 unknown) Source: https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=aa243282-d977-4d61-81a2-b81c17ac47f3 https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=aa243282-d977-4d61-81a2-b81c17ac47f3 Page 2 of 2