Rotexy

MITRE ATT&CK: S0411 View on attack.mitre.org

Aliases: Rotexy

First seen
2014-10-01 00:00:00
Malware type
ransomware, spyware, trojan
Family
Malware family
Operating systems
android
Profile updated
2026-07-07 15:29:35

Targeted industries: financial-services

Context

Rotexy is an Android banking malware that has evolved over several years. It was originally an SMS spyware Trojan first spotted in October 2014, and since then has evolved to contain more features, including ransomware functionality.

Malware & tools used

  • Contact List (attack-pattern)
  • Out of Band Data (attack-pattern)
  • System Checks (attack-pattern)
  • Domain Generation Algorithms (attack-pattern)
  • Web Protocols (attack-pattern)
  • Software Discovery (attack-pattern)
  • Suppress Application Icon (attack-pattern)
  • Process Discovery (attack-pattern)
  • GUI Input Capture (attack-pattern)
  • Obfuscated Files or Information (attack-pattern)
  • SMS Messages (attack-pattern)
  • System Network Configuration Discovery (attack-pattern)
  • SMS Control (attack-pattern)
  • Device Lockout (attack-pattern)
  • System Information Discovery (attack-pattern)
  • Symmetric Cryptography (attack-pattern)

Reports & references

  • MITRE ATT&CK — S0411 (report)
  • Kaspersky — 88893 (report)

External references