mirror of
https://github.com/MBCProject/mbc-markdown
synced 2026-06-08 11:36:36 +00:00
009ae77217
* E/f updates (#143) * E/F Update, Update Install Cert ID * Small fixes * Update common objects link (#142) * Update README.md * Update 09152023.md * Update README.md * Update 12182023.md * Adding descriptions to micro-behaviors * Fixing dead links * V3.1 updates (#144) * minor fixes for v3.1 * correct id --------- Co-authored-by: Desiree Beck <dbeck@mitre.org>
1.7 KiB
1.7 KiB
| ID | X0012 |
| Type | Bot/Botnet, Wiper |
| Aliases | None |
| Platforms | Android |
| Year | 2016 |
| Associated ATT&CK Software | MazarBOT |
MazarBot
MazarBot targets Android phones via a poisoned text message.
ATT&CK Techniques
See ATT&CK: MazarBOT - Techniques Used.
Enhanced ATT&CK Techniques
| Name | Use |
|---|---|
| Impact::Data Destruction (E1485) | MazarBot can erase phone data. [3] |
MBC Behaviors
| Name | Use |
|---|---|
| Impact::Manipulate Network Traffic (B0019) | MazarBot intercepts data coming into and going out of the device. [1] |
| Execution::Install Additional Program (B0023) | MazarBot installs a backdoor. [1] |
| Execution::Send Poisoned Text Message (B0021) | MazarBot is delivered via a poisoned SMS message. [2] |
Indicators of Compromise
SHA256 Hashes
- 0432a460b1af4a31c0b0ab12106886ff9e5fd1b7a109c1a9e5ab29b4fafd6719
References
[1] https://us.norton.com/internetsecurity-emerging-threats-mazar-bot-malware-invades-and-erases-android-devices.html
[2] https://www.player.one/stub-56857
[3] https://heimdalsecurity.com/blog/security-alert-mazar-bot-active-attacks-android-malware/