Movatterモバイル変換


[0]ホーム

URL:


  1. Home
  2. Software
  3. Desert Scorpion

Desert Scorpion

Desert Scorpion is surveillanceware that has targeted the Middle East, specifically individuals located in Palestine.Desert Scorpion is suspected to have been operated by the threat actorAPT-C-23.[1]

There are multiple close variants ofDesert Scorpion, such as VAMP[2], GnatSpy[3],FrozenCell andSpyC23, which add some additional functionality but are not significantly different from the original malware.

ID: S0505
Type: MALWARE
Platforms: Android
Version: 1.2
Created: 11 September 2020
Last Modified: 13 January 2025
Mobile Layer
downloadview

Techniques Used

DomainIDNameUse
MobileT1532Archive Collected Data

Desert Scorpion can encrypt exfiltrated data.[1]

MobileT1429Audio Capture

Desert Scorpion can record audio from phone calls and the device microphone.[1]

MobileT1533Data from Local System

Desert Scorpion can collect attacker-specified files, including files located on external storage.[1]

MobileT1407Download New Code at Runtime

Desert Scorpion has been distributed in multiple stages.[1]

MobileT1420File and Directory Discovery

Desert Scorpion can list files stored on external storage.[1]

MobileT1628.001Hide Artifacts:Suppress Application Icon

Desert Scorpion can hide its icon.[1]

MobileT1630.002Indicator Removal on Host:File Deletion

Desert Scorpion can delete copies of itself if additional APKs are downloaded to external storage.[1]

MobileT1430Location Tracking

Desert Scorpion can track the device’s location.[1]

MobileT1644Out of Band Data

Desert Scorpion can be controlled using SMS messages.[1]

MobileT1636.003Protected User Data:Contact List

Desert Scorpion can collect the device’s contact list.[1]

.004Protected User Data:SMS Messages

Desert Scorpion can retrieve SMS messages.[1]

MobileT1582SMS Control

Desert Scorpion can send SMS messages.[1]

MobileT1418Software Discovery

Desert Scorpion can obtain a list of installed applications.[1]

MobileT1409Stored Application Data

Desert Scorpion can collect account information stored on the device.[1]

MobileT1632.001Subvert Trust Controls:Code Signing Policy Modification

If running on a Huawei device,Desert Scorpion adds itself to the protected apps list, which allows it to run with the screen off.[1]

MobileT1426System Information Discovery

Desert Scorpion can collect device metadata and can check if the device is rooted.[1]

MobileT1512Video Capture

Desert Scorpion can record videos.[1]

Groups That Use This Software

IDNameReferences
G1028APT-C-23

References

×

[8]ページ先頭

©2009-2026 Movatter.jp