Android
Essential information
- Confidence
- 100/100
- Is family
- No
- Published
- 20/12/2025 19:34
- Modified
- 20/12/2025 21:07
- Revoked
- No
- Author / Source
- AlienVault
- Related entities
- 21 attack patterns (mitre), 2 intrusion sets (apt), 19 countries, 23 indicators
Description
No description.
Marking (TLP)
TLP:CLEAR
Related entities
Attack patterns, malware, vulnerabilities, indicators, intrusion sets and other entities linked to this malware.
Attack patterns (MITRE) (21)
-
Access Notifications usesT1517 MITRE
-
T1082 usesSystem Information Discovery MITRE
-
T1476 MITRE
-
Audio Capture usesT1429 MITRE
-
T1422 MITRE
-
T1090 usesProxy MITRE
-
T1040 usesNetwork Sniffing MITRE
-
Non-Standard Port usesT1509 MITRE
-
T1571 usesNon-Standard Port MITRE
-
T1433 uses
-
Location Tracking usesT1430 MITRE
-
T1412 uses
Intrusion sets (APT) (2)
-
The MITRE Corporation Confidence 100
[Windshift](https://attack.mitre.org/groups/G0112) is a threat group that has been active since at least 2017, targeting specific individuals for surveillance in government departments and critical infrastructure across the Middle East.(Citation:…
First seen 01/01/1970 · Last seen 16/11/5138 · -
The MITRE Corporation Confidence 100
[Ke3chang](https://attack.mitre.org/groups/G0004) is a threat group attributed to actors operating out of China. [Ke3chang](https://attack.mitre.org/groups/G0004) has targeted oil, government, diplomatic, military, and NGOs in Central and South America, the Caribbean,…
First seen 01/01/1970 · Last seen 16/11/5138 ·
Countries (19)
-
Hungary targets
-
United States of America targets
-
Germany targets
-
Spain targets
-
Ukraine targets
-
Australia targets
-
Singapore targets
-
Netherlands targets
-
Portugal targets
-
Georgia targets
-
Denmark targets
-
Lithuania targets
Indicators (23)
-
stix 100/100 Revoked
SHA256 of fb63cfb371dbb79fde2f2b2835bb0edba4b5e5a6
· Valid until 03/10/2023 · Source: AlienVault -
https://gkcx6ye4t4zafw8ju2xdr5na5.deindicatesstix 100/100 Revoked· Valid until 16/08/2022 · Source: AlienVault -
gkcx6ye4t4zafw8ju2xdr5na5.deindicatesstix 100/100 Revoked· Valid until 26/04/2023 · Source: AlienVault -
stix 100/100 Revoked
SHA256 of 44b7cd8d1078a619356d5408bcf9d325d246ec26
· Valid until 03/10/2023 · Source: AlienVault -
stix 100/100 Revoked· Valid until 06/02/2023 · Source: AlienVault
-
stix 100/100 Revoked· Valid until 16/08/2022 · Source: AlienVault