INSOMNIA

MITRE ATT&CK: S0463 View on attack.mitre.org

Aliases: INSOMNIA

First seen
2021-05-15 00:00:00
Malware type
spyware
Family
Malware family
Operating systems
ios
Profile updated
2026-07-07 14:01:57

Targeted industries: government-and-public-sector financial-services technology-and-telecommunications

Targeted regions: country_code:cn country_code:ua country_code:ru

Context

INSOMNIA is spyware that has been used by the group Evil Eye.

Malware & tools used

  • System Information Discovery (attack-pattern)
  • Exploitation for Privilege Escalation (attack-pattern)
  • Location Tracking (attack-pattern)
  • Ptrace System Calls (attack-pattern)
  • Obfuscated Files or Information (attack-pattern)
  • SMS Messages (attack-pattern)
  • System Network Configuration Discovery (attack-pattern)
  • Software Discovery (attack-pattern)
  • Internet Connection Discovery (attack-pattern)
  • Non-Standard Port (attack-pattern)
  • Wi-Fi Discovery (attack-pattern)
  • Contact List (attack-pattern)
  • Call Log (attack-pattern)
  • Web Protocols (attack-pattern)
  • Data from Local System (attack-pattern)
  • Keychain (attack-pattern)
  • Drive-By Compromise (attack-pattern)

Reports & references

  • ransomlook.io — Insomnia (report)
  • MITRE ATT&CK — S0463 (report)
  • volexity.com — Evil Eye Threat Actor Resurfaces With Ios Exploit And Updated Implant (report)

External references