Skip to content

Latest commit

 

History

History
60 lines (43 loc) · 1.61 KB

mazarbot.md

File metadata and controls

60 lines (43 loc) · 1.61 KB
ID X0012
Aliases None
Platforms Android
Year 2016
Associated ATT&CK Software MazarBOT

MazarBot

Targets Android phones via a poisoned text message.

ATT&CK Techniques

See ATT&CK: MazarBOT - Techniques Used.

Enhanced ATT&CK Techniques

Name Use
Impact::Data Destruction (E1485) Can erase phone data [3]

MBC Behaviors

Name Use
Impact::Manipulate Network Traffic (B0019) Intercepts data coming into and going out of device [1]
Execution::Install Additional Program (B0023) Installs a backdoor [1]
Execution::Send Poisoned Text Message (B0021) Can send SMS messages [2]

Indicators of Compromise

SHA256 Hashes

  • 0432a460b1af4a31c0b0ab12106886ff9e5fd1b7a109c1a9e5ab29b4fafd6719

References

[1] https://us.norton.com/internetsecurity-emerging-threats-mazar-bot-malware-invades-and-erases-android-devices.html

[2] https://www.player.one/new-android-sms-malware-can-completely-own-your-phone-just-one-text-how-avoid-mazar-512363

[3] https://heimdalsecurity.com/blog/security-alert-mazar-bot-active-attacks-android-malware/