X-Agent for Android
MITRE ATT&CK: S0314 View on attack.mitre.org
- First seen
- 2014-12-01 00:00:00
- Malware type
- spyware, rat
- Family
- Malware family
- Profile updated
- 2026-07-07 15:27:57
Targeted industries: defense-and-aerospace government-and-public-sector
Targeted regions: country_code:ua
Context
X-Agent for Android is Android malware that was placed in a repackaged version of a Ukrainian artillery targeting application. The malware reportedly retrieved general location data on where the victim device was used, and therefore could likely indicate the potential location of Ukrainian artillery. Is it tracked separately from the CHOPSTICK.
Malware & tools used
- Match Legitimate Name or Location (attack-pattern)
- Location Tracking (attack-pattern)
Used by threat actors
- APT28 (threat-actor)
Related threat objects
- X-Agent (Android) (malware)
Reports & references
- MITRE ATT&CK — S0314 (report)
- CrowdStrike — Fancybeartracksukrainianartillery (report)
External references
- mitre-attack — S0314
- X-Agent for Android
- CrowdStrike-Android
- misp-galaxy
- misp-galaxy