Center for Threat-Informed Defense

Version 15.1 16.0

Software : Mobile ATT&CK Changelog

Modified Software

Description

FinFisher is a government-grade commercial surveillance spyware reportedly sold exclusively to government agencies for use in targeted and lawful criminal investigations. It is heavily obfuscated and uses multiple anti-analysis techniques. It has other variants including Wingbird. [1] [2] [3] [4] [5]

References:

  1. FinFisher. (n.d.). Retrieved September 12, 2024.
  2. Anthe, C. et al. (2016, December 14). Microsoft Security Intelligence Report Volume 21. Retrieved November 27, 2017.
  3. Jiang, G., et al. (2017, September 12). FireEye Uncovers CVE-2017-8759: Zero-Day Used in the Wild to Distribute FINSPY. Retrieved February 15, 2018.
  4. Kaspersky Lab's Global Research & Analysis Team. (2017, October 16). BlackOasis APT and new targeted attacks leveraging zero-day exploit. Retrieved February 15, 2018.
  5. Allievi, A.,Flori, E. (2018, March 01). FinFisher exposed: A researcher’s tale of defeating traps, tricks, and complex virtual machines. Retrieved July 9, 2018.
Details
Dictionary Item Added
FIELD OLD VALUE NEW VALUE
x_mitre_deprecated False
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2022-03-02 15:47:13.329000+00:00 2024-09-12 17:23:46.687000+00:00
external_references[3]['description'] FinFisher. (n.d.). Retrieved December 20, 2017. FinFisher. (n.d.). Retrieved September 12, 2024.
external_references[3]['url'] http://www.finfisher.com/FinFisher/index.html https://web.archive.org/web/20171222050934/http://www.finfisher.com/FinFisher/index.html
x_mitre_attack_spec_version 2.1.0 3.2.0

Description

Anubis is Android malware that was originally used for cyber espionage, and has been retooled as a banking trojan.[1]

References:

  1. M. Feller. (2020, February 5). Infostealer, Keylogger, and Ransomware in One: Anubis Targets More than 250 Android Applications. Retrieved September 25, 2024.
Details
Dictionary Item Added
FIELD OLD VALUE NEW VALUE
x_mitre_deprecated False
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2021-09-20 13:50:01.923000+00:00 2024-09-25 15:03:05.100000+00:00
external_references[1]['description'] M. Feller. (2020, February 5). Infostealer, Keylogger, and Ransomware in One: Anubis Targets More than 250 Android Applications. Retrieved April 8, 2020. M. Feller. (2020, February 5). Infostealer, Keylogger, and Ransomware in One: Anubis Targets More than 250 Android Applications. Retrieved September 25, 2024.
external_references[1]['url'] https://cofense.com/infostealer-keylogger-ransomware-one-anubis-targets-250-android-applications/ https://web.archive.org/web/20231222134431/https://cofense.com/blog/infostealer-keylogger-ransomware-one-anubis-targets-250-android-applications/
x_mitre_attack_spec_version 2.1.0 3.2.0

Description

Exobot is Android banking malware, primarily targeting financial institutions in Germany, Austria, and France.[1]

References:

  1. Threat Fabric. (2017, February). Exobot - Android banking Trojan on the rise. Retrieved October 29, 2020.
Details
Dictionary Item Added
FIELD OLD VALUE NEW VALUE
x_mitre_deprecated False
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2020-12-07 14:28:31.876000+00:00 2024-10-01 15:53:53.833000+00:00
x_mitre_attack_spec_version 2.1.0 3.2.0
Iterable Item Removed
FIELD OLD VALUE NEW VALUE
external_references {'source_name': 'Proofpoint-Marcher', 'description': 'Proofpoint. (2017, November 3). Credential phishing and an Android banking Trojan combine in Austrian mobile attacks. Retrieved July 6, 2018.', 'url': 'https://www.proofpoint.com/us/threat-insight/post/credential-phishing-and-android-banking-trojan-combine-austrian-mobile-attacks'}
x_mitre_aliases Marcher

Deprecated Software

Description

Marcher is Android malware that is used for financial fraud. [1]

References:

  1. Proofpoint. (2017, November 3). Credential phishing and an Android banking Trojan combine in Austrian mobile attacks. Retrieved July 6, 2018.
Details
Dictionary Item Added
FIELD OLD VALUE NEW VALUE
x_mitre_aliases ['Marcher']
x_mitre_deprecated True
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2022-10-24 15:09:07.609000+00:00 2024-09-30 18:57:47.266000+00:00
x_mitre_attack_spec_version 2.1.0 3.2.0