SecurityCipher
Home Blog About Us
Resources ▼
✅ Security Checklists Hub 🗺️ Penetration Testing Roadmap 🤖 OWASP Top 10 for LLM Applications 🧠 LLM AI Security Checklist 🛠️ Security Tools 🎯 Penetration Testing Tricks 📄 Secure Code Explain 📖 Vulnerability Explain ☁️ AWS Cloud Security Checklist
My Resume
Our ServicesServices
New On-Call Drive Drive the neon city, jack in, and clear security tickets Play now →
← Security Tools View on GitHub

Quark-Engine

Android malware scoring and analysis system that is obfuscation-neutral.

Black Hat Arsenal Black Hat Arsenal HITB defcon
build status codecov license python version PyPi Download
Twitter

Malware Family Analysis Report Showcase

FamilySummarySignature BehaviorsReport
DroidKungFuPrivilege escalation with C2 control.1. Gain unlimited access to a device.
2. Install/Uninstall additional apps.
3. Forward confidential data.
View
GoldDreamSMS/call log exfiltration with remote C2 commands.1. Monitor SMS messages and phone calls.
2. Upload SMS messages and phone calls to remote servers.
View
SpyNoteCredential theft and device surveillance via RAT.1. Take screenshots.
2. Simulate user gestures.
3. Log user input.
4. Communicate with C2 servers.
View
DawDropperDropper that installs banking trojans for financial theft.1. Download APKs from remote servers.
2. Install additional APKs.
View
SLockerAndroid ransomware locking/encrypting devices.1. Lock the device with an overlay screen.View
PhantomCardNFC relay–based financial fraud.1. Communicate with C2 servers.
2. Read the payment data of NFC cards.
3. Captures PINs of NFC cards through deceptive screens.
View
ToxicPandaBanking trojan enabling on-device fraud.1. Abuse Accessibility.
2. Remote device control.
3. Intercept OTP.
View
HydraBanking trojan using overlay attacks.1. Overlay credential theft.
2. Accessibility abuse.
3. Steal OTP/cookies.
View
SharkBotBanking trojan targeting financial credentials and transactions.1. Abuse Accessibility services.
2. Perform overlay attacks to steal credentials.
3. Intercept SMS messages (OTP).
View
AntidotBanking trojan disguised as legitimate updates for financial data theft.1. Intercept SMS messages (OTP).
2. Log user input (keylogging).
3. Enable remote control via C2.
View
ArsinkBanking trojan focusing on credential and financial data exfiltration.1. Steal sensitive data from device.
2. Intercept SMS messages (OTP).
View
TrickMoBanking trojan using overlay attacks and accessibility abuse for credential theft.1. Overlay attacks to steal banking credentials.
2. Intercept SMS for 2FA bypass.
3. Screen recording and accessibility abuse.
4. Dynamic payload loading via reflection.
View
AnubisBanking trojan with RAT capabilities.1. Overlay credential theft.
2. Keylogging.
3. Intercept SMS (OTP).
4. Remote control via C2.
View
GodFatherBanking trojan targeting financial credentials through overlay and accessibility abuse.1. Perform overlay attacks to steal credentials.
2. Abuse Accessibility services.
3. Intercept SMS messages (OTP).
4. Steal banking credentials and sensitive data.
View
TangleBotSMS-based Android malware stealing personal and financial data.1. Spread through SMS phishing links.
2. Control device interactions and overlay screens.
3. Access SMS, contacts, call logs, camera, and microphone.
4. Steal account and financial information.
View
BRATABanking trojan with remote control and anti-analysis capabilities.1. Perform overlay attacks to steal banking credentials.
2. Abuse Accessibility services for device control.
3. Intercept SMS messages (OTP).
4. Execute factory reset or device wipe commands.
View
CerberusBanking trojan targeting financial credentials through overlay and device control.1. Perform overlay attacks to steal credentials.
2. Abuse Accessibility services.
3. Log user input (keylogging).
4. Enable remote control via C2.
View
SuperCardXNFC relay malware enabling contactless payment fraud.1. Read NFC payment card data.
2. Relay NFC transactions to attacker-controlled devices.
3. Communicate with C2 servers.
4. Facilitate unauthorized contactless payments.
View
NGateNFC-based malware enabling relay attacks and payment fraud.1. Read NFC payment card data.
2. Relay NFC communications to attacker-controlled devices.
3. Communicate with C2 servers.
4. Facilitate unauthorized contactless payments.
View
AhRatAndroid RAT capable of surveillance and data theft.1. Record audio from the device.
2. Steal files and sensitive data.
3. Remote access via C2.
4. Execute remote commands.
View
AndroRatAndroid remote access trojan for device surveillance.1. Record audio and capture video.
2. Track device location.
3. Steal files and device information.
4. Execute remote commands.
View
SovaAndroid banking trojan distributed as trojanised carrier apps for credential theft and SMS fraud.1. Read device identifiers via the C2 ping-response handler.
2. Inject outbound SMS on operator command.
3. Place phone calls without user consent.
View
EventBotBanking trojan and infostealer targeting 200+ financial apps.1. Enumerate installed applications to pick targets.
2. Intercept incoming SMS via a broadcast receiver.
3. Exfiltrate SMS bodies over HTTP to defeat 2FA.
View
SkygofreeAndroid spyware designed for surveillance and sensitive data collection.1. Capture audio.
2. Access stored application data.
3. Download new code at runtime.
4. Capture video.
View

Quick Start

Step 1. Install via PyPi

Install the latest version of Quark Engine:

$ pip3 install -U quark-engine

Step 2. Download Latest Rules

Fetch the latest rule database:

$ freshquark

Step 3. Run Summary Report

Analyze an APK with the downloaded rules and generate a summary report:

$ quark -a <apk_file> -s

Step 4. View Results

Example output: Screenshot-2025-11-25-22-36-54

Quark-Engine Skills

Quark-Engine also ships two Claude Code skills:

  • /quark:analysis — analyze an APK with Quark-Engine
  • /quark:rule-gen — generate a Quark rule from decompiled code

To install, run these commands inside Claude Code after installing Quark-Engine:

/plugin marketplace add ev-flow/quark-engine
/plugin install quark@quark-engine

The skills then should appear.

Acknowledgments

The Honeynet Project

Honeynet.org logo

Google Summer Of Code

Quark-Engine has been participating in the GSoC under the Honeynet Project!

  • 2021:
    • YuShiang Dang: New Rule Generation Technique & Make Quark Everywhere Among Security Open Source Projects
    • Sheng-Feng Lu: Replace the core library of Quark-Engine

Stay tuned for the upcoming GSoC! Join the Honeynet Slack chat for more info.

Core Values of Quark Engine Team

  • We love battle fields. We embrace uncertainties. We challenge impossibles. We rethink everything. We change the way people think. And the most important of all, we benefit ourselves by benefit others first.

Penetration Testing Services

penetration Testing Services

Web Application Security Quiz

Web Application Security Quiz

Daily Bug Bounty Writeups - Twitter

Daily Bug Bounty Writeups

Download our Latest Android Application

Guide for Penetration Testing

Daily Bug Bounty Writeups - Telegram

Daily Bug Bounty Writeups

Author

Piyush
Senior Product Security Engineer

Ethical Hacker || Penetration Tester || Gamer || Blogger || Product Security Engineer || AI Security

READ ARTICLE

Donate

Buy me a Coffee

Recent Posts

  • Cloud Misconfig Bounty Hunting in 2026: Open Buckets, Firebase, and Secrets
    Cloud Misconfig Bounty Hunting in 2026: Open Buckets, Firebase, and Secrets
    September 8, 2026/
    0 Comments
  • DevSecOps From Laptop to Production: A Practical Security Pipeline Guide
    DevSecOps From Laptop to Production: A Practical Security Pipeline Guide
    August 27, 2026/
    0 Comments
  • The CVE Flood Is a Lie: How to Hunt When AI Dumps 36% More Bugs But Exploitation Only Grows 10%
    The CVE Flood Is a Lie: How to Hunt When AI Dumps 36% More Bugs But Exploitation Only Grows 10%
    August 25, 2026/
    0 Comments

Follow Us

SecurityCipher

Practical security guides, vulnerability deep-dives, and hands-on resources for bug bounty hunters and penetration testers.

Useful Links

  • Security Checklists
  • Cybersecurity Jobs
  • Blogs
  • About
  • Contact
© 2026 SecurityCipher. All rights reserved. Privacy Policies · Terms & Conditions