Concipit1248

MITRE ATT&CK: S0426 View on attack.mitre.org

Aliases: Corona Updates, Concipit1248

First seen
2023-09-15 00:00:00
Malware type
spyware
Family
Malware family
Operating systems
ios
Profile updated
2026-07-07 15:28:19

Targeted industries: government-and-public-sector technology-and-telecommunications

Context

Concipit1248 is iOS spyware that was discovered using the same name as the developer of the Android spyware Corona Updates. Further investigation revealed that the two pieces of software contained the same C2 URL and similar functionality.

Malware & tools used

  • Web Protocols (attack-pattern)
  • Video Capture (attack-pattern)
  • Data from Local System (attack-pattern)

Reports & references

  • Trend Micro — Coronavirus Update App Leads To Project Spy Android And Ios Spyware (report)
  • MITRE ATT&CK — S0426 (report)

External references