Mandrake

MITRE ATT&CK: S0485 View on attack.mitre.org

Aliases: oxide, briar, ricinus, darkmatter, Mandrake

First seen
2016-01-01 00:00:00
Malware type
spyware, rat
Family
Malware family
Operating systems
android
Profile updated
2026-07-07 14:08:18

Targeted industries: financial-services government-and-public-sector

Context

Mandrake is a sophisticated Android espionage platform that has been active in the wild since at least 2016. Mandrake is very actively maintained, with sophisticated features and attacks that are executed with surgical precision. Mandrake has gone undetected for several years by providing legitimate, ad-free applications with social media and real reviews to back the apps. The malware is only activated when the operators issue a specific command.

Malware & tools used

  • Match Legitimate Name or Location (attack-pattern)
  • Contact List (attack-pattern)
  • System Checks (attack-pattern)
  • Access Notifications (attack-pattern)
  • Foreground Persistence (attack-pattern)
  • Stored Application Data (attack-pattern)
  • Non-Standard Port (attack-pattern)
  • SMS Control (attack-pattern)
  • Screen Capture (attack-pattern)
  • Disable or Modify Tools (attack-pattern)
  • Obfuscated Files or Information (attack-pattern)
  • Prevent Application Removal (attack-pattern)
  • Bidirectional Communication (attack-pattern)
  • Input Injection (attack-pattern)
  • Location Tracking (attack-pattern)
  • Software Discovery (attack-pattern)
  • GUI Input Capture (attack-pattern)
  • Code Signing Policy Modification (attack-pattern)
  • Suppress Application Icon (attack-pattern)
  • Download New Code at Runtime (attack-pattern)
  • Domain Generation Algorithms (attack-pattern)
  • File Deletion (attack-pattern)
  • System Information Discovery (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)
  • SMS Messages (attack-pattern)

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Apk.Mandrake (report)
  • bitdefender.com — Bitdefender Pr Whitepaper Mandrake Creat4464 En En Interactive (report)
  • MITRE ATT&CK — S0485 (report)

External references