Files
Ryan Xu 009ae77217 3.1 Updates (#145)
* E/f updates (#143)

* E/F Update,  Update Install Cert ID

* Small fixes

* Update common objects link (#142)

* Update README.md

* Update 09152023.md

* Update README.md

* Update 12182023.md

* Adding descriptions to micro-behaviors

* Fixing dead links

* V3.1 updates (#144)

* minor fixes for v3.1

* correct id

---------

Co-authored-by: Desiree Beck <dbeck@mitre.org>
2024-02-14 09:27:20 -05:00

1.7 KiB

ID X0012
Type Bot/Botnet, Wiper
Aliases None
Platforms Android
Year 2016
Associated ATT&CK Software MazarBOT

MazarBot

MazarBot targets Android phones via a poisoned text message.

ATT&CK Techniques

See ATT&CK: MazarBOT - Techniques Used.

Enhanced ATT&CK Techniques

Name Use
Impact::Data Destruction (E1485) MazarBot can erase phone data. [3]

MBC Behaviors

Name Use
Impact::Manipulate Network Traffic (B0019) MazarBot intercepts data coming into and going out of the device. [1]
Execution::Install Additional Program (B0023) MazarBot installs a backdoor. [1]
Execution::Send Poisoned Text Message (B0021) MazarBot is delivered via a poisoned SMS message. [2]

Indicators of Compromise

SHA256 Hashes

  • 0432a460b1af4a31c0b0ab12106886ff9e5fd1b7a109c1a9e5ab29b4fafd6719

References

[1] https://us.norton.com/internetsecurity-emerging-threats-mazar-bot-malware-invades-and-erases-android-devices.html

[2] https://www.player.one/stub-56857

[3] https://heimdalsecurity.com/blog/security-alert-mazar-bot-active-attacks-android-malware/