Trusted Design

Exodus: New Android Spyware Made in Italy

概要

Security Without Borders identified a new Android spyware platform we named Exodus, which is composed of two stages we call Exodus One and Exodus Two. We have collected numerous samples spanning from 2016 to early 2019. Instances of this spyware were found on the Google Play Store, disguised as service applications from mobile operators. Both the Google Play Store pages and the decoys of the malicious apps are in Italian. According to publicly available statistics, as well as confirmation from Google, most of these apps collected a few dozens installations each, with one case reaching over 350. All of the victims are located in Italy. All of these Google Play Store pages have been taken down by Google. Security Without Borders believes this spyware platform is developed by an Italian company called eSurv, which primarily operates in the business of video surveillance. According to public records it appears that eSurv began to also develop intrusion software in 2016.

Created: 2026-02-23

Indicators

類似Pulses

このPulseに関連する脅威アクター (事実ベース)

Mustard Tempest

Score: 4.54
Matched TTPs:
  • T1583.008 - Malvertising
MITREへのリンク →

TA505

Score: 3.62
Matched TTPs:
  • T1087.003 - Email Account
MITREへのリンク →

Magic Hound

Score: 7.10
Matched TTPs:
  • T1087.003 - Email Account
  • T1036.004 - Masquerade Task or Service
  • T1070.004 - File Deletion
MITREへのリンク →

RedCurl

Score: 7.75
Matched TTPs:
  • T1087.003 - Email Account
  • T1573.002 - Asymmetric Cryptography
  • T1070.004 - File Deletion
MITREへのリンク →

Sandworm Team

Score: 8.62
Matched TTPs:
  • T1087.003 - Email Account
  • T1584.005 - Botnet
  • T1070.004 - File Deletion
MITREへのリンク →

Dragonfly

Score: 3.97
Matched TTPs:
  • T1560 - Archive Collected Data
  • T1070.004 - File Deletion
MITREへのリンク →

Patchwork

Score: 7.26
Matched TTPs:
  • T1560 - Archive Collected Data
  • T1070.004 - File Deletion
  • T1102.001 - Dead Drop Resolver
MITREへのリンク →

Axiom

Score: 6.21
Matched TTPs:
  • T1560 - Archive Collected Data
  • T1584.005 - Botnet
MITREへのリンク →

Ember Bear

Score: 7.82
Matched TTPs:
  • T1560 - Archive Collected Data
  • T1125 - Video Capture
  • T1070.004 - File Deletion
MITREへのリンク →

BlackByte

Score: 3.97
Matched TTPs:
  • T1560 - Archive Collected Data
  • T1070.004 - File Deletion
MITREへのリンク →

Lazarus Group

Score: 9.69
Matched TTPs:
  • T1560 - Archive Collected Data
  • T1036.004 - Masquerade Task or Service
  • T1104 - Multi-Stage Channels
  • T1070.004 - File Deletion
MITREへのリンク →

APT28

Score: 8.11
Matched TTPs:
  • T1560 - Archive Collected Data
  • T1070.004 - File Deletion
  • T1211 - Exploitation for Defense Evasion
MITREへのリンク →

APT32

Score: 8.81
Matched TTPs:
  • T1560 - Archive Collected Data
  • T1036.004 - Masquerade Task or Service
  • T1218.010 - Regsvr32
  • T1070.004 - File Deletion
MITREへのリンク →

FIN6

Score: 8.81
Matched TTPs:
  • T1560 - Archive Collected Data
  • T1036.004 - Masquerade Task or Service
  • T1573.002 - Asymmetric Cryptography
  • T1070.004 - File Deletion
MITREへのリンク →

menuPass

Score: 3.97
Matched TTPs:
  • T1560 - Archive Collected Data
  • T1070.004 - File Deletion
MITREへのリンク →

Leviathan

Score: 5.34
Matched TTPs:
  • T1560 - Archive Collected Data
  • T1218.010 - Regsvr32
MITREへのリンク →

Scattered Spider

Score: 11.60
Matched TTPs:
  • T1580 - Cloud Infrastructure Discovery
  • T1074 - Data Staged
  • T1213.005 - Messaging Applications
MITREへのリンク →

Storm-0501

Score: 8.97
Matched TTPs:
  • T1580 - Cloud Infrastructure Discovery
  • T1036.004 - Masquerade Task or Service
  • T1218.010 - Regsvr32
MITREへのリンク →

Silence

Score: 5.23
Matched TTPs:
  • T1125 - Video Capture
  • T1070.004 - File Deletion
MITREへのリンク →

FIN7

Score: 5.94
Matched TTPs:
  • T1125 - Video Capture
  • T1036.004 - Masquerade Task or Service
MITREへのリンク →

Aquatic Panda

Score: 3.48
Matched TTPs:
  • T1036.004 - Masquerade Task or Service
  • T1070.004 - File Deletion
MITREへのリンク →

Kimsuky

Score: 9.51
Matched TTPs:
  • T1036.004 - Masquerade Task or Service
  • T1218.010 - Regsvr32
  • T1070.004 - File Deletion
  • T1102.001 - Dead Drop Resolver
MITREへのリンク →

Wizard Spider

Score: 7.10
Matched TTPs:
  • T1036.004 - Masquerade Task or Service
  • T1074 - Data Staged
  • T1070.004 - File Deletion
MITREへのリンク →

Fox Kitten

Score: 5.94
Matched TTPs:
  • T1036.004 - Masquerade Task or Service
  • T1213.005 - Messaging Applications
MITREへのリンク →

UNC3886

Score: 3.48
Matched TTPs:
  • T1036.004 - Masquerade Task or Service
  • T1070.004 - File Deletion
MITREへのリンク →

APT41

Score: 10.38
Matched TTPs:
  • T1036.004 - Masquerade Task or Service
  • T1104 - Multi-Stage Channels
  • T1070.004 - File Deletion
  • T1102.001 - Dead Drop Resolver
MITREへのリンク →

Volt Typhoon

Score: 8.62
Matched TTPs:
  • T1074 - Data Staged
  • T1584.005 - Botnet
  • T1070.004 - File Deletion
MITREへのリンク →

INC Ransom

Score: 5.00
Matched TTPs:
  • T1074 - Data Staged
  • T1070.004 - File Deletion
MITREへのリンク →

HAFNIUM

Score: 3.62
Matched TTPs:
  • T1584.005 - Botnet
MITREへのリンク →

APT3

Score: 5.00
Matched TTPs:
  • T1104 - Multi-Stage Channels
  • T1070.004 - File Deletion
MITREへのリンク →

MuddyWater

Score: 3.62
Matched TTPs:
  • T1104 - Multi-Stage Channels
MITREへのリンク →

Cobalt Group

Score: 6.87
Matched TTPs:
  • T1218.010 - Regsvr32
  • T1573.002 - Asymmetric Cryptography
  • T1070.004 - File Deletion
MITREへのリンク →

OilRig

Score: 8.67
Matched TTPs:
  • T1137.004 - Outlook Home Page
  • T1573.002 - Asymmetric Cryptography
  • T1070.004 - File Deletion
MITREへのリンク →

Velvet Ant

Score: 6.88
Matched TTPs:
  • T1573.002 - Asymmetric Cryptography
  • T1211 - Exploitation for Defense Evasion
MITREへのリンク →

Tropic Trooper

Score: 4.13
Matched TTPs:
  • T1573.002 - Asymmetric Cryptography
  • T1070.004 - File Deletion
MITREへのリンク →

Medusa Group

Score: 8.67
Matched TTPs:
  • T1573.002 - Asymmetric Cryptography
  • T1070.004 - File Deletion
  • T1218.014 - MMC
MITREへのリンク →

FIN8

Score: 4.13
Matched TTPs:
  • T1573.002 - Asymmetric Cryptography
  • T1070.004 - File Deletion
MITREへのリンク →

BRONZE BUTLER

Score: 4.67
Matched TTPs:
  • T1070.004 - File Deletion
  • T1102.001 - Dead Drop Resolver
MITREへのリンク →

Rocke

Score: 4.67
Matched TTPs:
  • T1070.004 - File Deletion
  • T1102.001 - Dead Drop Resolver
MITREへのリンク →

Equation

Score: 4.13
Matched TTPs:
  • T1564.005 - Hidden File System
MITREへのリンク →

Strider

Score: 4.13
Matched TTPs:
  • T1564.005 - Hidden File System
MITREへのリンク →

RTM

Score: 3.29
Matched TTPs:
  • T1102.001 - Dead Drop Resolver
MITREへのリンク →

LAPSUS$

Score: 3.84
Matched TTPs:
  • T1213.005 - Messaging Applications
MITREへのリンク →

このPulseに関連する脅威アクター (推論ベース)

Scattered Spider

Score: 0.81
Matched TTPs:
  • T1074 - Data Staged
  • T1213.005 - Messaging Applications
  • T1580 - Cloud Infrastructure Discovery
MITREへのリンク →

APT41

Score: 0.77
Matched TTPs:
  • T1036.004 - Masquerade Task or Service
  • T1104 - Multi-Stage Channels
  • T1102.001 - Dead Drop Resolver
  • T1070.004 - File Deletion
MITREへのリンク →

Lazarus Group

Score: 0.71
Matched TTPs:
  • T1036.004 - Masquerade Task or Service
  • T1104 - Multi-Stage Channels
  • T1560 - Archive Collected Data
  • T1070.004 - File Deletion
MITREへのリンク →

Storm-0501

Score: 0.68
Matched TTPs:
  • T1036.004 - Masquerade Task or Service
  • T1580 - Cloud Infrastructure Discovery
  • T1218.010 - Regsvr32
MITREへのリンク →

Kimsuky

Score: 0.67
Matched TTPs:
  • T1036.004 - Masquerade Task or Service
  • T1102.001 - Dead Drop Resolver
  • T1218.010 - Regsvr32
  • T1070.004 - File Deletion
MITREへのリンク →

Medusa Group

Score: 0.66
Matched TTPs:
  • T1218.014 - MMC
  • T1573.002 - Asymmetric Cryptography
  • T1070.004 - File Deletion
MITREへのリンク →

APT32

Score: 0.65
Matched TTPs:
  • T1036.004 - Masquerade Task or Service
  • T1560 - Archive Collected Data
  • T1218.010 - Regsvr32
  • T1070.004 - File Deletion
MITREへのリンク →

FIN6

Score: 0.64
Matched TTPs:
  • T1036.004 - Masquerade Task or Service
  • T1573.002 - Asymmetric Cryptography
  • T1560 - Archive Collected Data
  • T1070.004 - File Deletion
MITREへのリンク →

OilRig

Score: 0.63
Matched TTPs:
  • T1137.004 - Outlook Home Page
  • T1573.002 - Asymmetric Cryptography
  • T1070.004 - File Deletion
MITREへのリンク →

Sandworm Team

Score: 0.62
Matched TTPs:
  • T1584.005 - Botnet
  • T1087.003 - Email Account
  • T1070.004 - File Deletion
MITREへのリンク →

Volt Typhoon

Score: 0.62
Matched TTPs:
  • T1584.005 - Botnet
  • T1074 - Data Staged
  • T1070.004 - File Deletion
MITREへのリンク →

APT28

Score: 0.59
Matched TTPs:
  • T1211 - Exploitation for Defense Evasion
  • T1560 - Archive Collected Data
  • T1070.004 - File Deletion
MITREへのリンク →

RedCurl

Score: 0.57
Matched TTPs:
  • T1573.002 - Asymmetric Cryptography
  • T1087.003 - Email Account
  • T1070.004 - File Deletion
MITREへのリンク →

Ember Bear

Score: 0.56
Matched TTPs:
  • T1125 - Video Capture
  • T1560 - Archive Collected Data
  • T1070.004 - File Deletion
MITREへのリンク →

Patchwork

Score: 0.56
Matched TTPs:
  • T1102.001 - Dead Drop Resolver
  • T1560 - Archive Collected Data
  • T1070.004 - File Deletion
MITREへのリンク →

Related CVEs

このPulseに見つかったCVEはありません。

Pulse – 脅威アクター グラフ


← Pulse一覧に戻る