SimBad

MITRE ATT&CK: S0419 View on attack.mitre.org

Aliases: SimBad

First seen
2019-03-13 00:00:00
Family
Malware family
Operating systems
android
Profile updated
2026-07-07 15:30:25

Targeted industries: media-and-entertainment technology-and-telecommunications

Context

SimBad was a strain of adware on the Google Play Store, distributed through the RXDroider Software Development Kit. The name "SimBad" was derived from the fact that most of the infected applications were simulator games. The adware was controlled using an instance of the open source framework Parse Server.

Malware & tools used

  • Broadcast Receivers (attack-pattern)
  • Generate Traffic from Victim (attack-pattern)
  • Match Legitimate Name or Location (attack-pattern)
  • Suppress Application Icon (attack-pattern)

Reports & references

  • MITRE ATT&CK — S0419 (report)
  • research.checkpoint.com — Simbad A Rogue Adware Campaign On Google Play (report)

External references