Movatterモバイル変換


[0]ホーム

URL:


  1. Home
  2. Software
  3. BusyGasper

BusyGasper

BusyGasper is Android spyware that has been in use since May 2016. There have been less than 10 victims, all who appear to be located in Russia, that were all infected via physical access to the device.[1]

ID: S0655
Type: MALWARE
Platforms: Android
Version: 1.0
Created: 01 October 2021
Last Modified: 16 April 2025
Mobile Layer
downloadview

Techniques Used

DomainIDNameUse
MobileT1429Audio Capture

BusyGasper can record audio.[1]

MobileT1616Call Control

BusyGasper can open a hidden menu when a specific phone number is called from the infected device.[1]

MobileT1623.001Command and Scripting Interpreter:Unix Shell

BusyGasper can run shell commands.[1]

MobileT1645Compromise Client Software Binary

BusyGasper can abuse existing root access to copy components into the system partition.[1]

MobileT1533Data from Local System

BusyGasper can collect images stored on the device and browser history.[1]

MobileT1407Download New Code at Runtime

BusyGasper can download a payload or updates from either its C2 server or email attachments in the adversary’s inbox.[1]

MobileT1639.001Exfiltration Over Alternative Protocol:Exfiltration Over Unencrypted Non-C2 Protocol

BusyGasper can download text files with commands from an FTP server and exfiltrate data via email.[1]

MobileT1628.001Hide Artifacts:Suppress Application Icon

BusyGasper can hide its icon.[1]

.002Hide Artifacts:User Evasion

BusyGasper can utilize the device’s sensors to determine when the device is in use and subsequently hide malicious activity. When active, it attempts to hide its malicious activity by turning the screen’s brightness as low as possible and muting the device.[1]

MobileT1417.001Input Capture:Keylogging

BusyGasper can collect every user screen tap and compare the input to a hardcoded list of coordinates to translate the input to a character.[1]

MobileT1430Location Tracking

BusyGasper can collect the device’s location information based on cellular network or GPS coordinates.[1]

MobileT1644Out of Band Data

BusyGasper can perform actions when one of two hardcoded magic SMS strings is received.[1]

MobileT1636.004Protected User Data:SMS Messages

BusyGasper can collect SMS messages.[1]

MobileT1513Screen Capture

BusyGasper can use its keylogger module to take screenshots of the area of the screen that the user tapped.[1]

MobileT1582SMS Control

BusyGasper can send an SMS message after the device boots, messages containing logs, messages to adversary-specified numbers with custom content, and can delete all SMS messages on the device.[1]

MobileT1409Stored Application Data

BusyGasper can collect data from messaging applications, including WhatsApp, Viber, and Facebook.[1]

MobileT1512Video Capture

BusyGasper can record from the device’s camera.[1]

MobileT1481.002Web Service:Bidirectional Communication

BusyGasper can be controlled via IRC using freenode.net servers.[1]

References

×

[8]ページ先頭

©2009-2026 Movatter.jp