Skygofree: Following in the footsteps of HackingTeam
概要
At the beginning of October 2017, we discovered new Android spyware with several features previously unseen in the wild. In the course of further research, we found a number of related samples that point to a long-term development process. We believe the initial versions of this malware were created at least three years ago – at the end of 2014. Since then, the implant’s functionality has been improving and remarkable new features implemented, such as the ability to record audio surroundings via the microphone when an infected device is in a specified location; the stealing of WhatsApp messages via Accessibility Services; and the ability to connect an infected device to Wi-Fi networks controlled by cybercriminals.
Created: 2026-02-23
Indicators
類似Pulses
このPulseに関連する脅威アクター (事実ベース)
Score: 8.97
Matched TTPs:
- T1069 - Permission Groups Discovery
- T1569.002 - Service Execution
- T1102.001 - Dead Drop Resolver
MITREへのリンク →
Score: 10.57
Matched TTPs:
- T1069 - Permission Groups Discovery
- T1598 - Phishing for Information
- T1136 - Create Account
MITREへのリンク →
Score: 3.29
Matched TTPs:
- T1069 - Permission Groups Discovery
MITREへのリンク →
Score: 10.01
Matched TTPs:
- T1069 - Permission Groups Discovery
- T1614 - System Location Discovery
- T1124 - System Time Discovery
MITREへのリンク →
Score: 3.29
Matched TTPs:
- T1069 - Permission Groups Discovery
MITREへのリンク →
Score: 3.29
Matched TTPs:
- T1069 - Permission Groups Discovery
MITREへのリンク →
Score: 3.03
Matched TTPs:
- T1091 - Replication Through Removable Media
MITREへのリンク →
Score: 3.03
Matched TTPs:
- T1091 - Replication Through Removable Media
MITREへのリンク →
Score: 3.03
Matched TTPs:
- T1091 - Replication Through Removable Media
MITREへのリンク →
Score: 5.63
Matched TTPs:
- T1091 - Replication Through Removable Media
- T1124 - System Time Discovery
MITREへのリンク →
Score: 10.32
Matched TTPs:
- T1091 - Replication Through Removable Media
- T1588.003 - Code Signing Certificates
- T1027.007 - Dynamic API Resolution
MITREへのリンク →
Score: 11.87
Matched TTPs:
- T1091 - Replication Through Removable Media
- T1125 - Video Capture
- T1569.002 - Service Execution
- T1124 - System Time Discovery
MITREへのリンク →
Score: 11.01
Matched TTPs:
- T1091 - Replication Through Removable Media
- T1598 - Phishing for Information
- T1669 - Wi-Fi Networks
MITREへのリンク →
Score: 3.03
Matched TTPs:
- T1091 - Replication Through Removable Media
MITREへのリンク →
Score: 6.24
Matched TTPs:
- T1125 - Video Capture
- T1569.002 - Service Execution
MITREへのリンク →
Score: 11.26
Matched TTPs:
- T1574.013 - KernelCallbackTable
- T1027.007 - Dynamic API Resolution
- T1124 - System Time Discovery
MITREへのリンク →
Score: 3.15
Matched TTPs:
- T1055.012 - Process Hollowing
MITREへのリンク →
Score: 6.30
Matched TTPs:
- T1055.012 - Process Hollowing
- T1588.003 - Code Signing Certificates
MITREへのリンク →
Score: 6.44
Matched TTPs:
- T1055.012 - Process Hollowing
- T1102.001 - Dead Drop Resolver
MITREへのリンク →
Score: 5.55
Matched TTPs:
- T1055.012 - Process Hollowing
- T1569.002 - Service Execution
MITREへのリンク →
Score: 3.15
Matched TTPs:
- T1055.012 - Process Hollowing
MITREへのリンク →
Score: 3.15
Matched TTPs:
- T1055.012 - Process Hollowing
MITREへのリンク →
Score: 16.87
Matched TTPs:
- T1055.012 - Process Hollowing
- T1598 - Phishing for Information
- T1588.003 - Code Signing Certificates
- T1587 - Develop Capabilities
- T1102.001 - Dead Drop Resolver
MITREへのリンク →
Score: 7.69
Matched TTPs:
- T1137.004 - Outlook Home Page
- T1588.003 - Code Signing Certificates
MITREへのリンク →
Score: 4.13
Matched TTPs:
- T1614 - System Location Discovery
MITREへのリンク →
Score: 6.03
Matched TTPs:
- T1598 - Phishing for Information
- T1124 - System Time Discovery
MITREへのリンク →
Score: 9.68
Matched TTPs:
- T1598 - Phishing for Information
- T1587 - Develop Capabilities
- T1569.002 - Service Execution
MITREへのリンク →
Score: 4.54
Matched TTPs:
- T1608.006 - SEO Poisoning
MITREへのリンク →
Score: 5.55
Matched TTPs:
- T1588.003 - Code Signing Certificates
- T1569.002 - Service Execution
MITREへのリンク →
Score: 3.15
Matched TTPs:
- T1588.003 - Code Signing Certificates
MITREへのリンク →
Score: 3.15
Matched TTPs:
- T1588.003 - Code Signing Certificates
MITREへのリンク →
Score: 3.84
Matched TTPs:
- T1587 - Develop Capabilities
MITREへのリンク →
Score: 4.99
Matched TTPs:
- T1569.002 - Service Execution
- T1124 - System Time Discovery
MITREへのリンク →
Score: 6.94
Matched TTPs:
- T1569.002 - Service Execution
- T1574.012 - COR_PROFILER
MITREへのリンク →
Score: 5.88
Matched TTPs:
- T1124 - System Time Discovery
- T1102.001 - Dead Drop Resolver
MITREへのリンク →
Score: 3.29
Matched TTPs:
- T1102.001 - Dead Drop Resolver
MITREへのリンク →
Score: 3.29
Matched TTPs:
- T1102.001 - Dead Drop Resolver
MITREへのリンク →
このPulseに関連する脅威アクター (推論ベース)
Score: 0.78
Matched TTPs:
- T1588.003 - Code Signing Certificates
- T1055.012 - Process Hollowing
- T1587 - Develop Capabilities
- T1598 - Phishing for Information
- T1102.001 - Dead Drop Resolver
MITREへのリンク →
Score: 0.62
Matched TTPs:
- T1569.002 - Service Execution
- T1124 - System Time Discovery
- T1091 - Replication Through Removable Media
- T1125 - Video Capture
MITREへのリンク →
Score: 0.55
Matched TTPs:
- T1027.007 - Dynamic API Resolution
- T1574.013 - KernelCallbackTable
- T1124 - System Time Discovery
MITREへのリンク →
Related CVEs
このPulseに見つかったCVEはありません。
Pulse – 脅威アクター グラフ
← Pulse一覧に戻る