Agent Smith

MITRE ATT&CK: S0440 View on attack.mitre.org

Aliases: Agent Smith

Malware type
trojan
Family
Malware family
Operating systems
android
Profile updated
2026-07-07 14:03:20

Targeted industries: financial-services retail-and-hospitality

Targeted regions: country_code:in country_code:sa country_code:gb country_code:us

Context

Agent Smith is mobile malware that generates financial gain by replacing legitimate applications on devices with malicious versions that include fraudulent ads. As of July 2019 Agent Smith had infected around 25 million devices, primarily targeting India though effects had been observed in other Asian countries as well as Saudi Arabia, the United Kingdom, and the United States.

Malware & tools used

  • Generate Traffic from Victim (attack-pattern)
  • Process Discovery (attack-pattern)
  • Software Discovery (attack-pattern)
  • Suppress Application Icon (attack-pattern)
  • File Deletion (attack-pattern)
  • Exploitation for Privilege Escalation (attack-pattern)
  • Match Legitimate Name or Location (attack-pattern)
  • Compromise Application Executable (attack-pattern)
  • Steganography (attack-pattern)

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Apk.Agentsmith (report)
  • research.checkpoint.com — Agent Smith A New Species Of Mobile Malware (report)
  • MITRE ATT&CK — S0440 (report)

External references