Exodus
The MITRE Corporation
· Published 03/09/2019 21:45 · Modified 27/03/2026 01:41
Family
Essential information
- Confidence
- 100/100
- Is family
- Yes
- Published
- 03/09/2019 21:45
- Modified
- 27/03/2026 01:41
- Revoked
- No
- Author / Source
- The MITRE Corporation
- Related entities
- 38 attack patterns (mitre), 2 sectors, 9 countries, 73 indicators
Aliases
Exodus One Exodus Two
Description
[Exodus](https://attack.mitre.org/software/S0405) is Android spyware deployed in two distinct stages named Exodus One (dropper) and Exodus Two (payload).(Citation: SWB Exodus March 2019)
Marking (TLP)
TLP:CLEAR Copyright 2015-2025, The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation.
External references
Related entities
Attack patterns, malware, vulnerabilities, indicators, intrusion sets and other entities linked to this malware.
Attack patterns (MITRE) (38)
-
SMS Messages uses
-
T1003 usesOS Credential Dumping MITRE
-
Call Log uses
-
T1204 usesUser Execution MITRE
-
Audio Capture usesT1429 MITRE
-
Calendar Entries uses
-
T1532 MITRE
-
T1140 usesDeobfuscate/Decode Files or Information MITRE
-
Non-Standard Port usesT1509 MITRE
-
Web Protocols uses
-
T1115 usesClipboard Data MITRE
-
T1421 MITRE
Sectors (2)
-
Defense ministries (including the military) targets
-
Manufacturing targets
Countries (9)
-
Italy targets
-
India targets
-
Egypt targets
-
United States of America targets
-
Germany targets
-
Brazil targets
-
Russian Federation targets
-
Turkey targets
-
France targets
Indicators (73)
-
stix 100/100 Revoked
ALFPER:HSTR:WizzJSON SHA256 of 98f0556a846f223352da516af66fa1a0
· Valid until 01/01/2024 · Source: AlienVault -
stix 100/100 Revoked
Win32:CrypterX-gen\ [Trj] SHA256 of 4d75dea49f6bd60f725fae9c28cd0960
· Valid until 01/01/2024 · Source: AlienVault -
buy-fantasy-fo0tball.com.sgindicatesstix 100/100 Revoked· Valid until 25/07/2023 · Source: AlienVault -
all-mobile-pa1ments.com.mxindicatesstix 100/100 Revoked· Valid until 25/07/2023 · Source: AlienVault -
stix 100/100 Revoked
SHA256 of c41a85123af144790520f502fe190110
· Valid until 01/01/2024 · Source: AlienVault -
real-enter-solutions.xyzindicatesstix 100/100 Revoked· Valid until 25/07/2023 · Source: AlienVault -
stix 100/100 Revoked
SHA256 of 4feba8683daa18545e9f9408e4cd07bd
· Valid until 01/01/2024 · Source: AlienVault