DEFENSOR ID

MITRE ATT&CK: S0479 View on attack.mitre.org

Aliases: Defensor Digital, DEFENSOR ID

Malware type
trojan, credential-stealer
Family
Malware family
Operating systems
android
Related IoCs
1 (1 malicious)
Last IoC activity
2026-09-02 00:48:00
Profile updated
2026-07-07 13:44:50

Targeted industries: financial-services

Context

DEFENSOR ID is a banking trojan capable of clearing a victim’s bank account or cryptocurrency wallet and taking over email or social media accounts. DEFENSOR ID performs the majority of its malicious functionality by abusing Android’s accessibility service.

Recent IoC activity

1 malicious indicator in Maltiverse are attributed to DEFENSOR ID (S0479). The 1 most recently updated:

TypeIndicatorUpdatedSources
file sample 220603-jqrzpsdbg4.bin 2026-09-02 2

Malware & tools used

  • Screen Capture (attack-pattern)
  • Input Injection (attack-pattern)
  • Software Discovery (attack-pattern)
  • Web Protocols (attack-pattern)
  • Broadcast Receivers (attack-pattern)

Reports & references

  • ESET — Eset Threat Report Q22020 (report)
  • malpedia.caad.fkie.fraunhofer.de — Apk.Defensor Id (report)
  • ESET — Insidious Android Malware Gives Up All Malicious Features But One Gain Stealth (report)
  • MITRE ATT&CK — S0479 (report)

External references