Android
Essential information
- Confidence
- 100/100
- Is family
- No
- Published
- 20/12/2025 19:34
- Modified
- 20/12/2025 21:07
- Revoked
- No
- Author / Source
- AlienVault
- Related entities
- 21 attack patterns (mitre), 2 intrusion sets (apt), 19 countries, 23 indicators
Description
No description.
Marking (TLP)
TLP:CLEAR
Related entities
Attack patterns, malware, vulnerabilities, indicators, intrusion sets and other entities linked to this malware.
Attack patterns (MITRE) (21)
-
Access Notifications usesT1517 MITRE
-
T1082 usesSystem Information Discovery MITRE
-
T1476 MITRE
-
Audio Capture usesT1429 MITRE
-
T1422 MITRE
-
T1090 usesProxy MITRE
-
T1040 usesNetwork Sniffing MITRE
-
Non-Standard Port usesT1509 MITRE
-
T1571 usesNon-Standard Port MITRE
-
T1433 uses
-
Location Tracking usesT1430 MITRE
-
T1412 uses
Intrusion sets (APT) (2)
-
The MITRE Corporation Confidence 100
[Windshift](https://attack.mitre.org/groups/G0112) is a threat group that has been active since at least 2017, targeting specific individuals for surveillance in government departments and critical infrastructure across the Middle East.(Citation:…
First seen 01/01/1970 · Last seen 16/11/5138 · -
The MITRE Corporation Confidence 100
[Ke3chang](https://attack.mitre.org/groups/G0004) is a threat group attributed to actors operating out of China. [Ke3chang](https://attack.mitre.org/groups/G0004) has targeted oil, government, diplomatic, military, and NGOs in Central and South America, the Caribbean,…
First seen 01/01/1970 · Last seen 16/11/5138 ·
Countries (19)
-
Hungary targets
-
United States of America targets
-
Germany targets
-
Spain targets
-
Ukraine targets
-
Australia targets
-
Singapore targets
-
Netherlands targets
-
Portugal targets
-
Georgia targets
-
Denmark targets
-
Lithuania targets
Indicators (23)
-
https://www.securechatnow.com/indicatesstix 100/100 Revoked· Valid until 16/08/2022 · Source: AlienVault -
stix 100/100 Revoked
SHA256 of db2b2d2d43064b2a5300c811d635dbf673599b0c
· Valid until 03/10/2023 · Source: AlienVault -
https://www.iminglechat.deindicatesstix 100/100 Revoked· Valid until 16/08/2022 · Source: AlienVault -
stix 100/100 Revoked
xor_0x20_xord_javascript SHA256 of e368db837edf340e47e85652d6159d6e90725b0d
· Valid until 03/12/2024 · Source: AlienVault