ATT&CKSoftwareMobileOrder

MobileOrder

S0079

Malware.View on attack.mitre.org

About this malware

MobileOrder is a Trojan intended to compromise Android mobile devices. It has been used by Scarlet Mimic.

Techniques used7

Procedure examples7

TechniqueProcedure example
T1005
Data from Local System

MobileOrder exfiltrates data collected from the victim mobile device.

T1041
Exfiltration Over C2 Channel

MobileOrder exfiltrates data to its C2 server over the same protocol as C2 communications.

T1057
Process Discovery

MobileOrder has a command to upload information about all running processes to its C2 server.

T1082
System Information Discovery

MobileOrder has a command to upload to its C2 server victim mobile device information, including IMEI, IMSI, SIM card serial number, phone number, Android version, and other information.

T1083
File and Directory Discovery

MobileOrder has a command to upload to its C2 server information about files on the victim mobile device, including SD card size, installed app list, SMS content, contacts, and calling history.

T1105
Ingress Tool Transfer

MobileOrder has a command to download a file from the C2 server to the victim mobile device's SD card.

T1217
Browser Information Discovery

MobileOrder has a command to upload to its C2 server victim browser bookmarks.

Groups that use it1

Campaigns0

None recorded.

References1

  1. Scarlet Mimic Jan 2016 Open source
    Falcone, R. and Miller-Osborn, J.. (2016, January 24). Scarlet Mimic: Years-Long Espionage Campaign Targets Minority Activists. Retrieved February 10, 2016.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.