Trusted Design

Exaspy – Commodity Android Spyware Targeting High-level Executives

概要

Early September, Skycure Research Labs detected a fake app within one of our customer’s organizations, identified through our crowd-sourced intelligence policies (whereby anyone running the Skycure mobile app acts as a threat detecting sensor). This customer is a global technology company, which deployed Skycure’s Enterprise Mobile Threat Defense solution for all iOS and Android devices within their organization. This incident happened on an Android 6.0.1 device, owned by one of the company’s Vice Presidents. The customer has given us approval to share some of the details about the Spyware app that Skycure discovered.

Created: 2026-02-23

Indicators

類似Pulses

このPulseに関連する脅威アクター (事実ベース)

Ember Bear

Score: 12.71
Matched TTPs:
  • T1491.002 - External Defacement
  • T1195 - Supply Chain Compromise
  • T1190 - Exploit Public-Facing Application
  • T1203 - Exploitation for Client Execution
  • T1046 - Network Service Discovery
MITREへのリンク →

Sandworm Team

Score: 15.78
Matched TTPs:
  • T1491.002 - External Defacement
  • T1587.001 - Malware
  • T1195 - Supply Chain Compromise
  • T1190 - Exploit Public-Facing Application
  • T1199 - Trusted Relationship
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

APT41

Score: 8.01
Matched TTPs:
  • T1069 - Permission Groups Discovery
  • T1190 - Exploit Public-Facing Application
  • T1203 - Exploitation for Client Execution
  • T1046 - Network Service Discovery
MITREへのリンク →

Scattered Spider

Score: 14.84
Matched TTPs:
  • T1069 - Permission Groups Discovery
  • T1217 - Browser Information Discovery
  • T1556.009 - Conditional Access Policies
  • T1578.002 - Create Cloud Instance
MITREへのリンク →

TA505

Score: 3.29
Matched TTPs:
  • T1069 - Permission Groups Discovery
MITREへのリンク →

Volt Typhoon

Score: 9.81
Matched TTPs:
  • T1069 - Permission Groups Discovery
  • T1190 - Exploit Public-Facing Application
  • T1217 - Browser Information Discovery
  • T1046 - Network Service Discovery
MITREへのリンク →

APT3

Score: 7.93
Matched TTPs:
  • T1069 - Permission Groups Discovery
  • T1027.005 - Indicator Removal from Tools
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

FIN13

Score: 8.62
Matched TTPs:
  • T1069 - Permission Groups Discovery
  • T1587.001 - Malware
  • T1190 - Exploit Public-Facing Application
  • T1046 - Network Service Discovery
MITREへのリンク →

Kimsuky

Score: 3.57
Matched TTPs:
  • T1587.001 - Malware
  • T1190 - Exploit Public-Facing Application
MITREへのリンク →

Moonstone Sleet

Score: 7.90
Matched TTPs:
  • T1587.001 - Malware
  • T1217 - Browser Information Discovery
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

Lazarus Group

Score: 7.88
Matched TTPs:
  • T1587.001 - Malware
  • T1203 - Exploitation for Client Execution
  • T1046 - Network Service Discovery
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

Contagious Interview

Score: 8.75
Matched TTPs:
  • T1587.001 - Malware
  • T1681 - Search Threat Vendor Data
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

OilRig

Score: 14.87
Matched TTPs:
  • T1587.001 - Malware
  • T1195 - Supply Chain Compromise
  • T1027.005 - Indicator Removal from Tools
  • T1203 - Exploitation for Client Execution
  • T1046 - Network Service Discovery
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

UNC3886

Score: 12.34
Matched TTPs:
  • T1587.001 - Malware
  • T1190 - Exploit Public-Facing Application
  • T1681 - Search Threat Vendor Data
  • T1027.005 - Indicator Removal from Tools
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

LuminousMoth

Score: 5.13
Matched TTPs:
  • T1587.001 - Malware
  • T1091 - Replication Through Removable Media
MITREへのリンク →

Salt Typhoon

Score: 3.57
Matched TTPs:
  • T1587.001 - Malware
  • T1190 - Exploit Public-Facing Application
MITREへのリンク →

APT29

Score: 10.33
Matched TTPs:
  • T1587.001 - Malware
  • T1190 - Exploit Public-Facing Application
  • T1199 - Trusted Relationship
  • T1203 - Exploitation for Client Execution
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

Play

Score: 3.57
Matched TTPs:
  • T1587.001 - Malware
  • T1190 - Exploit Public-Facing Application
MITREへのリンク →

Aoqin Dragon

Score: 6.62
Matched TTPs:
  • T1587.001 - Malware
  • T1091 - Replication Through Removable Media
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

RedCurl

Score: 6.61
Matched TTPs:
  • T1587.001 - Malware
  • T1199 - Trusted Relationship
  • T1046 - Network Service Discovery
MITREへのリンク →

Moses Staff

Score: 3.57
Matched TTPs:
  • T1587.001 - Malware
  • T1190 - Exploit Public-Facing Application
MITREへのリンク →

Turla

Score: 5.25
Matched TTPs:
  • T1587.001 - Malware
  • T1027.005 - Indicator Removal from Tools
MITREへのリンク →

Ke3chang

Score: 3.57
Matched TTPs:
  • T1587.001 - Malware
  • T1190 - Exploit Public-Facing Application
MITREへのリンク →

Mustang Panda

Score: 8.39
Matched TTPs:
  • T1587.001 - Malware
  • T1091 - Replication Through Removable Media
  • T1203 - Exploitation for Client Execution
  • T1046 - Network Service Discovery
MITREへのリンク →

TeamTNT

Score: 8.40
Matched TTPs:
  • T1587.001 - Malware
  • T1610 - Deploy Container
  • T1046 - Network Service Discovery
MITREへのリンク →

FIN7

Score: 6.60
Matched TTPs:
  • T1587.001 - Malware
  • T1091 - Replication Through Removable Media
  • T1190 - Exploit Public-Facing Application
MITREへのリンク →

Gamaredon Group

Score: 3.03
Matched TTPs:
  • T1091 - Replication Through Removable Media
MITREへのリンク →

Darkhotel

Score: 4.53
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

APT28

Score: 8.74
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1190 - Exploit Public-Facing Application
  • T1199 - Trusted Relationship
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

Tropic Trooper

Score: 6.29
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1203 - Exploitation for Client Execution
  • T1046 - Network Service Discovery
MITREへのリンク →

Rocke

Score: 3.24
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1046 - Network Service Discovery
MITREへのリンク →

Threat Group-3390

Score: 7.47
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1199 - Trusted Relationship
  • T1203 - Exploitation for Client Execution
  • T1046 - Network Service Discovery
MITREへのリンク →

BackdoorDiplomacy

Score: 3.24
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1046 - Network Service Discovery
MITREへのリンク →

GOLD SOUTHFIELD

Score: 4.22
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1199 - Trusted Relationship
MITREへのリンク →

BlackTech

Score: 4.73
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1203 - Exploitation for Client Execution
  • T1046 - Network Service Discovery
MITREへのリンク →

Magic Hound

Score: 5.76
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1046 - Network Service Discovery
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

Medusa Group

Score: 3.24
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1046 - Network Service Discovery
MITREへのリンク →

Sea Turtle

Score: 5.71
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1199 - Trusted Relationship
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

Storm-0501

Score: 5.60
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1556.009 - Conditional Access Policies
MITREへのリンク →

Fox Kitten

Score: 6.52
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1217 - Browser Information Discovery
  • T1046 - Network Service Discovery
MITREへのリンク →

BlackByte

Score: 3.24
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1046 - Network Service Discovery
MITREへのリンク →

Agrius

Score: 3.24
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1046 - Network Service Discovery
MITREへのリンク →

menuPass

Score: 5.98
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1199 - Trusted Relationship
  • T1046 - Network Service Discovery
MITREへのリンク →

ToddyCat

Score: 3.99
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

GALLIUM

Score: 4.62
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1027.005 - Indicator Removal from Tools
MITREへのリンク →

INC Ransom

Score: 3.24
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1046 - Network Service Discovery
MITREへのリンク →

HAFNIUM

Score: 4.22
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1199 - Trusted Relationship
MITREへのリンク →

APT39

Score: 3.24
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1046 - Network Service Discovery
MITREへのリンク →

APT38

Score: 3.29
Matched TTPs:
  • T1217 - Browser Information Discovery
MITREへのリンク →

Chimera

Score: 5.05
Matched TTPs:
  • T1217 - Browser Information Discovery
  • T1046 - Network Service Discovery
MITREへのリンク →

LAPSUS$

Score: 6.88
Matched TTPs:
  • T1199 - Trusted Relationship
  • T1578.002 - Create Cloud Instance
MITREへのリンク →

Patchwork

Score: 4.65
Matched TTPs:
  • T1027.005 - Indicator Removal from Tools
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

Deep Panda

Score: 3.15
Matched TTPs:
  • T1027.005 - Indicator Removal from Tools
MITREへのリンク →

EXOTIC LILY

Score: 4.02
Matched TTPs:
  • T1203 - Exploitation for Client Execution
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

Cobalt Group

Score: 3.26
Matched TTPs:
  • T1203 - Exploitation for Client Execution
  • T1046 - Network Service Discovery
MITREへのリンク →

APT32

Score: 3.26
Matched TTPs:
  • T1203 - Exploitation for Client Execution
  • T1046 - Network Service Discovery
MITREへのリンク →

FIN6

Score: 4.29
Matched TTPs:
  • T1046 - Network Service Discovery
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

Mustard Tempest

Score: 4.54
Matched TTPs:
  • T1608.006 - SEO Poisoning
MITREへのリンク →

このPulseに関連する脅威アクター (推論ベース)

Sandworm Team

Score: 0.80
Matched TTPs:
  • T1195 - Supply Chain Compromise
  • T1491.002 - External Defacement
  • T1587.001 - Malware
  • T1190 - Exploit Public-Facing Application
  • T1199 - Trusted Relationship
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

Scattered Spider

Score: 0.77
Matched TTPs:
  • T1217 - Browser Information Discovery
  • T1556.009 - Conditional Access Policies
  • T1069 - Permission Groups Discovery
  • T1578.002 - Create Cloud Instance
MITREへのリンク →

OilRig

Score: 0.76
Matched TTPs:
  • T1027.005 - Indicator Removal from Tools
  • T1566.003 - Spearphishing via Service
  • T1195 - Supply Chain Compromise
  • T1587.001 - Malware
  • T1046 - Network Service Discovery
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

UNC3886

Score: 0.70
Matched TTPs:
  • T1027.005 - Indicator Removal from Tools
  • T1681 - Search Threat Vendor Data
  • T1587.001 - Malware
  • T1190 - Exploit Public-Facing Application
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

Ember Bear

Score: 0.64
Matched TTPs:
  • T1195 - Supply Chain Compromise
  • T1491.002 - External Defacement
  • T1190 - Exploit Public-Facing Application
  • T1046 - Network Service Discovery
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

APT29

Score: 0.56
Matched TTPs:
  • T1566.003 - Spearphishing via Service
  • T1587.001 - Malware
  • T1190 - Exploit Public-Facing Application
  • T1199 - Trusted Relationship
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

Related CVEs

このPulseに見つかったCVEはありません。

Pulse – 脅威アクター グラフ


← Pulse一覧に戻る