SpyDealer

MITRE ATT&CK: S0324 View on attack.mitre.org

Aliases: SpyDealer

Malware type
spyware
Family
Malware family
Operating systems
android
Profile updated
2026-07-07 15:30:38

Targeted industries: technology-and-telecommunications

Targeted regions: country_code:cn country_code:in

Context

SpyDealer is Android malware that exfiltrates sensitive data from Android devices.

Malware & tools used

  • Screen Capture (attack-pattern)
  • Download New Code at Runtime (attack-pattern)
  • Call Log (attack-pattern)
  • Compromise Client Software Binary (attack-pattern)
  • Out of Band Data (attack-pattern)
  • Stored Application Data (attack-pattern)
  • Location Tracking (attack-pattern)
  • Contact List (attack-pattern)
  • Exploitation for Privilege Escalation (attack-pattern)
  • Broadcast Receivers (attack-pattern)
  • SMS Messages (attack-pattern)
  • Audio Capture (attack-pattern)
  • System Network Configuration Discovery (attack-pattern)
  • Video Capture (attack-pattern)

Reports & references

  • MITRE ATT&CK — S0324 (report)
  • researchcenter.paloaltonetworks.com — Unit42 Spydealer Android Trojan Spying 40 Apps (report)

External references