Hornbill
Essential information
- Confidence
- 100/100
- Is family
- Yes
- Published
- 09/06/2023 21:07
- Modified
- 27/03/2026 01:41
- Revoked
- No
- Author / Source
- The MITRE Corporation
- Related entities
- 21 attack patterns (mitre), 1 intrusion sets (apt)
Description
[Hornbill](https://attack.mitre.org/software/S1077) is one of two mobile malware families known to be used by the APT [Confucius](https://attack.mitre.org/groups/G0142). Analysis suggests that [Hornbill](https://attack.mitre.org/software/S1077) was first active in early 2018. While [Hornbill](https://attack.mitre.org/software/S1077) and [Sunbird](https://attack.mitre.org/software/S1082) overlap in core capabilities, [Hornbill](https://attack.mitre.org/software/S1077) has tools and behaviors suggesting more passive reconnaissance.(Citation: lookout_hornbill_sunbird_0221)
Marking (TLP)
Copyright 2015-2025, The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation.