Agent Smith
MITRE ATT&CK: S0440 View on attack.mitre.org
Aliases: Agent Smith
- Malware type
- trojan
- Family
- Malware family
- Operating systems
- android
- Profile updated
- 2026-07-07 14:03:20
Targeted industries: financial-services retail-and-hospitality
Targeted regions: country_code:in country_code:sa country_code:gb country_code:us
Context
Agent Smith is mobile malware that generates financial gain by replacing legitimate applications on devices with malicious versions that include fraudulent ads. As of July 2019 Agent Smith had infected around 25 million devices, primarily targeting India though effects had been observed in other Asian countries as well as Saudi Arabia, the United Kingdom, and the United States.
Malware & tools used
- Generate Traffic from Victim (attack-pattern)
- Process Discovery (attack-pattern)
- Software Discovery (attack-pattern)
- Suppress Application Icon (attack-pattern)
- File Deletion (attack-pattern)
- Exploitation for Privilege Escalation (attack-pattern)
- Match Legitimate Name or Location (attack-pattern)
- Compromise Application Executable (attack-pattern)
- Steganography (attack-pattern)
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Apk.Agentsmith (report)
- research.checkpoint.com — Agent Smith A New Species Of Mobile Malware (report)
- MITRE ATT&CK — S0440 (report)