Rotexy
MITRE ATT&CK: S0411 View on attack.mitre.org
Aliases: Rotexy
- First seen
- 2014-10-01 00:00:00
- Malware type
- ransomware, spyware, trojan
- Family
- Malware family
- Operating systems
- android
- Profile updated
- 2026-07-07 15:29:35
Targeted industries: financial-services
Context
Rotexy is an Android banking malware that has evolved over several years. It was originally an SMS spyware Trojan first spotted in October 2014, and since then has evolved to contain more features, including ransomware functionality.
Malware & tools used
- Contact List (attack-pattern)
- Out of Band Data (attack-pattern)
- System Checks (attack-pattern)
- Domain Generation Algorithms (attack-pattern)
- Web Protocols (attack-pattern)
- Software Discovery (attack-pattern)
- Suppress Application Icon (attack-pattern)
- Process Discovery (attack-pattern)
- GUI Input Capture (attack-pattern)
- Obfuscated Files or Information (attack-pattern)
- SMS Messages (attack-pattern)
- System Network Configuration Discovery (attack-pattern)
- SMS Control (attack-pattern)
- Device Lockout (attack-pattern)
- System Information Discovery (attack-pattern)
- Symmetric Cryptography (attack-pattern)
Reports & references
- MITRE ATT&CK — S0411 (report)
- Kaspersky — 88893 (report)