Trusted Design

First Twitter-controlled Android botnet discovered

概要

Android/Twitoor is a backdoor capable of downloading other malware onto an infected device. It has been active for around one month. This malicious app, a variant of Android/Twitoor.A, can’t be found on any official Android app store – it probably spreads by SMS or via malicious URLs. It impersonates a porn player app or MMS application but without having their functionality. After launching, it hides its presence on the system and checks the defined Twitter account at regular intervals for commands. Based on received commands, it can either download malicious apps or switch the C&C Twitter account to another one.

Created: 2026-02-23

Indicators

類似Pulses

このPulseに関連する脅威アクター (事実ベース)

APT41

Score: 9.21
Matched TTPs:
  • T1560.003 - Archive via Custom Method
  • T1556.005 - Reversible Encryption
  • T1548.006 - TCC Manipulation
  • T1027.007 - Dynamic API Resolution
MITREへのリンク →

Scattered Spider

Score: 5.63
Matched TTPs:
  • T1560.003 - Archive via Custom Method
  • T1548.006 - TCC Manipulation
MITREへのリンク →

TA505

Score: 6.45
Matched TTPs:
  • T1560.003 - Archive via Custom Method
  • T1091 - Replication Through Removable Media
  • T1556.005 - Reversible Encryption
MITREへのリンク →

Volt Typhoon

Score: 9.25
Matched TTPs:
  • T1560.003 - Archive via Custom Method
  • T1049 - System Network Connections Discovery
  • T1548.006 - TCC Manipulation
MITREへのリンク →

APT3

Score: 6.91
Matched TTPs:
  • T1560.003 - Archive via Custom Method
  • T1578.002 - Create Cloud Instance
MITREへのリンク →

FIN13

Score: 6.81
Matched TTPs:
  • T1560.003 - Archive via Custom Method
  • T1556.005 - Reversible Encryption
  • T1548.006 - TCC Manipulation
MITREへのリンク →

Sandworm Team

Score: 15.65
Matched TTPs:
  • T1484.002 - Trust Modification
  • T1091 - Replication Through Removable Media
  • T1049 - System Network Connections Discovery
  • T1547.002 - Authentication Package
  • T1556.005 - Reversible Encryption
  • T1548.006 - TCC Manipulation
MITREへのリンク →

Leviathan

Score: 8.26
Matched TTPs:
  • T1484.002 - Trust Modification
  • T1554 - Compromise Host Software Binary
MITREへのリンク →

HAFNIUM

Score: 11.00
Matched TTPs:
  • T1027.008 - Stripped Payloads
  • T1049 - System Network Connections Discovery
  • T1556.005 - Reversible Encryption
  • T1548.006 - TCC Manipulation
MITREへのリンク →

APT5

Score: 3.84
Matched TTPs:
  • T1027.008 - Stripped Payloads
MITREへのリンク →

Ke3chang

Score: 9.77
Matched TTPs:
  • T1027.008 - Stripped Payloads
  • T1556.005 - Reversible Encryption
  • T1548.006 - TCC Manipulation
  • T1027.007 - Dynamic API Resolution
MITREへのリンク →

Earth Lusca

Score: 5.59
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1218.001 - Compiled HTML File
MITREへのリンク →

Mustang Panda

Score: 18.02
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1567.002 - Exfiltration to Cloud Storage
  • T1556.005 - Reversible Encryption
  • T1071.001 - Web Protocols
  • T1055.005 - Thread Local Storage
  • T1548.006 - TCC Manipulation
MITREへのリンク →

LuminousMoth

Score: 3.16
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1556.005 - Reversible Encryption
MITREへのリンク →

Kimsuky

Score: 13.13
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1654 - Log Enumeration
  • T1547.002 - Authentication Package
  • T1656 - Impersonation
  • T1556.005 - Reversible Encryption
MITREへのリンク →

OilRig

Score: 3.16
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1556.005 - Reversible Encryption
MITREへのリンク →

TeamTNT

Score: 3.16
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1556.005 - Reversible Encryption
MITREへのリンク →

Gamaredon Group

Score: 9.69
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1554 - Compromise Host Software Binary
  • T1547.002 - Authentication Package
  • T1556.005 - Reversible Encryption
MITREへのリンク →

Threat Group-3390

Score: 3.16
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1556.005 - Reversible Encryption
MITREへのリンク →

BlackByte

Score: 5.56
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1556.005 - Reversible Encryption
  • T1027.007 - Dynamic API Resolution
MITREへのリンク →

BITTER

Score: 3.16
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1556.005 - Reversible Encryption
MITREへのリンク →

APT32

Score: 5.56
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1556.005 - Reversible Encryption
  • T1027.007 - Dynamic API Resolution
MITREへのリンク →

HEXANE

Score: 4.37
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1547.002 - Authentication Package
MITREへのリンク →

Moonstone Sleet

Score: 5.56
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1556.005 - Reversible Encryption
  • T1027.007 - Dynamic API Resolution
MITREへのリンク →

Contagious Interview

Score: 5.41
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1656 - Impersonation
MITREへのリンク →

FIN7

Score: 6.77
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1547.002 - Authentication Package
  • T1027.007 - Dynamic API Resolution
MITREへのリンク →

APT42

Score: 3.16
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1556.005 - Reversible Encryption
MITREへのリンク →

Axiom

Score: 8.16
Matched TTPs:
  • T1049 - System Network Connections Discovery
  • T1160 - Launch Daemon
MITREへのリンク →

Dragonfly

Score: 10.09
Matched TTPs:
  • T1654 - Log Enumeration
  • T1578.002 - Create Cloud Instance
  • T1548.006 - TCC Manipulation
MITREへのリンク →

Lazarus Group

Score: 19.72
Matched TTPs:
  • T1069.001 - Local Groups
  • T1547.002 - Authentication Package
  • T1567.002 - Exfiltration to Cloud Storage
  • T1556.005 - Reversible Encryption
  • T1055.005 - Thread Local Storage
  • T1216 - System Script Proxy Execution
MITREへのリンク →

Turla

Score: 7.21
Matched TTPs:
  • T1218.001 - Compiled HTML File
  • T1547.002 - Authentication Package
  • T1556.005 - Reversible Encryption
MITREへのリンク →

CURIUM

Score: 3.62
Matched TTPs:
  • T1218.001 - Compiled HTML File
MITREへのリンク →

Winter Vivern

Score: 4.81
Matched TTPs:
  • T1218.001 - Compiled HTML File
  • T1556.005 - Reversible Encryption
MITREへのリンク →

APT37

Score: 7.21
Matched TTPs:
  • T1547.002 - Authentication Package
  • T1556.005 - Reversible Encryption
  • T1216 - System Script Proxy Execution
MITREへのリンク →

APT39

Score: 5.98
Matched TTPs:
  • T1547.002 - Authentication Package
  • T1556.005 - Reversible Encryption
  • T1027.007 - Dynamic API Resolution
MITREへのリンク →

Magic Hound

Score: 7.21
Matched TTPs:
  • T1547.002 - Authentication Package
  • T1578.002 - Create Cloud Instance
  • T1556.005 - Reversible Encryption
MITREへのリンク →

APT28

Score: 5.93
Matched TTPs:
  • T1547.002 - Authentication Package
  • T1556.005 - Reversible Encryption
  • T1548.006 - TCC Manipulation
MITREへのリンク →

MuddyWater

Score: 3.59
Matched TTPs:
  • T1547.002 - Authentication Package
  • T1556.005 - Reversible Encryption
MITREへのリンク →

Higaisa

Score: 5.03
Matched TTPs:
  • T1567.002 - Exfiltration to Cloud Storage
  • T1556.005 - Reversible Encryption
MITREへのリンク →

Fox Kitten

Score: 5.78
Matched TTPs:
  • T1656 - Impersonation
  • T1548.006 - TCC Manipulation
MITREへのリンク →

Ember Bear

Score: 3.44
Matched TTPs:
  • T1656 - Impersonation
MITREへのリンク →

APT17

Score: 3.44
Matched TTPs:
  • T1656 - Impersonation
MITREへのリンク →

Storm-1811

Score: 3.62
Matched TTPs:
  • T1578.002 - Create Cloud Instance
MITREへのリンク →

Chimera

Score: 5.93
Matched TTPs:
  • T1556.005 - Reversible Encryption
  • T1548.006 - TCC Manipulation
  • T1027.007 - Dynamic API Resolution
MITREへのリンク →

Medusa Group

Score: 14.09
Matched TTPs:
  • T1556.005 - Reversible Encryption
  • T1548.006 - TCC Manipulation
  • T1027.007 - Dynamic API Resolution
  • T1216 - System Script Proxy Execution
  • T1094 - Custom Command and Control Protocol
MITREへのリンク →

APT38

Score: 7.21
Matched TTPs:
  • T1556.005 - Reversible Encryption
  • T1027.007 - Dynamic API Resolution
  • T1216 - System Script Proxy Execution
MITREへのリンク →

Wizard Spider

Score: 5.93
Matched TTPs:
  • T1556.005 - Reversible Encryption
  • T1548.006 - TCC Manipulation
  • T1027.007 - Dynamic API Resolution
MITREへのリンク →

FIN6

Score: 4.74
Matched TTPs:
  • T1548.006 - TCC Manipulation
  • T1027.007 - Dynamic API Resolution
MITREへのリンク →

このPulseに関連する脅威アクター (推論ベース)

Lazarus Group

Score: 0.78
Matched TTPs:
  • T1069.001 - Local Groups
  • T1567.002 - Exfiltration to Cloud Storage
  • T1556.005 - Reversible Encryption
  • T1216 - System Script Proxy Execution
  • T1547.002 - Authentication Package
  • T1055.005 - Thread Local Storage
MITREへのリンク →

Mustang Panda

Score: 0.70
Matched TTPs:
  • T1548.006 - TCC Manipulation
  • T1567.002 - Exfiltration to Cloud Storage
  • T1556.005 - Reversible Encryption
  • T1071.001 - Web Protocols
  • T1091 - Replication Through Removable Media
  • T1055.005 - Thread Local Storage
MITREへのリンク →

Sandworm Team

Score: 0.63
Matched TTPs:
  • T1548.006 - TCC Manipulation
  • T1484.002 - Trust Modification
  • T1556.005 - Reversible Encryption
  • T1547.002 - Authentication Package
  • T1091 - Replication Through Removable Media
  • T1049 - System Network Connections Discovery
MITREへのリンク →

Medusa Group

Score: 0.58
Matched TTPs:
  • T1548.006 - TCC Manipulation
  • T1556.005 - Reversible Encryption
  • T1216 - System Script Proxy Execution
  • T1027.007 - Dynamic API Resolution
  • T1094 - Custom Command and Control Protocol
MITREへのリンク →

Related CVEs

このPulseに見つかったCVEはありません。

Pulse – 脅威アクター グラフ


← Pulse一覧に戻る