SimBad
MITRE ATT&CK: S0419 View on attack.mitre.org
Aliases: SimBad
- First seen
- 2019-03-13 00:00:00
- Family
- Malware family
- Operating systems
- android
- Profile updated
- 2026-07-07 15:30:25
Targeted industries: media-and-entertainment technology-and-telecommunications
Context
SimBad was a strain of adware on the Google Play Store, distributed through the RXDroider Software Development Kit. The name "SimBad" was derived from the fact that most of the infected applications were simulator games. The adware was controlled using an instance of the open source framework Parse Server.
Malware & tools used
- Broadcast Receivers (attack-pattern)
- Generate Traffic from Victim (attack-pattern)
- Match Legitimate Name or Location (attack-pattern)
- Suppress Application Icon (attack-pattern)
Reports & references
- MITRE ATT&CK — S0419 (report)
- research.checkpoint.com — Simbad A Rogue Adware Campaign On Google Play (report)