ViceLeaker

MITRE ATT&CK: S0418 View on attack.mitre.org

Aliases: Triout, ViceLeaker

Malware type
spyware
Family
Malware family
Operating systems
android
Last IoC activity
2026-06-26 10:56:22
Profile updated
2026-07-07 12:56:27

Targeted industries: government-and-public-sector

Targeted regions: country_code:il

Context

ViceLeaker is a spyware framework, capable of extensive surveillance and data exfiltration operations, primarily targeting devices belonging to Israeli citizens.

Malware & tools used

  • SMS Messages (attack-pattern)
  • System Information Discovery (attack-pattern)
  • Exfiltration Over C2 Channel (attack-pattern)
  • Software Discovery (attack-pattern)
  • Call Log (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)
  • Location Tracking (attack-pattern)
  • File Deletion (attack-pattern)
  • Match Legitimate Name or Location (attack-pattern)
  • Video Capture (attack-pattern)
  • Web Protocols (attack-pattern)
  • Data from Local System (attack-pattern)
  • Suppress Application Icon (attack-pattern)
  • Audio Capture (attack-pattern)

Reports & references

  • Kaspersky — 90877 (report)
  • MITRE ATT&CK — S0418 (report)
  • labs.bitdefender.com — Triout Spyware Framework For Android With Extensive Surveillance Capabilities (report)

External references