FlexiSpy

MITRE ATT&CK: S0408 View on attack.mitre.org

Aliases: FlexiSpy

Malware type
spyware
Family
Malware family
Operating systems
android
Related IoCs
1 (1 malicious)
Last IoC activity
2026-08-13 10:00:20
Profile updated
2026-07-07 15:32:34

Context

FlexiSpy is sophisticated surveillanceware for iOS and Android. Publicly-available, comprehensive analysis has only been found for the Android version. FlexiSpy markets itself as a parental control and employee monitoring application.

Recent IoC activity

1 malicious indicator in Maltiverse are attributed to FlexiSpy (S0408). The 1 most recently updated:

TypeIndicatorUpdatedSources
file sample flexispy.apk 2026-08-13 2

Malware & tools used

  • Screen Capture (attack-pattern)
  • Audio Capture (attack-pattern)
  • Stored Application Data (attack-pattern)
  • System Network Connections Discovery (attack-pattern)
  • Calendar Entries (attack-pattern)
  • Keylogging (attack-pattern)
  • Data from Local System (attack-pattern)
  • Suppress Application Icon (attack-pattern)
  • Non-Standard Port (attack-pattern)
  • Obfuscated Files or Information (attack-pattern)
  • Video Capture (attack-pattern)
  • Broadcast Receivers (attack-pattern)
  • Software Discovery (attack-pattern)
  • File Deletion (attack-pattern)
  • SMS Messages (attack-pattern)
  • Location Tracking (attack-pattern)
  • System Runtime API Hijacking (attack-pattern)
  • Contact List (attack-pattern)

Reports & references

  • cybermerchantsofdeath.com — Flexispy (report)
  • MITRE ATT&CK — S0408 (report)
  • d3gpjj9d20n0p3.cloudfront.net — Dig%20Deep%20Into%20Flexispy%20For%20Android%28White%20Paper%29 Kailu (report)
  • flexispy.com (report)

External references