Zen

MITRE ATT&CK: S0494 View on attack.mitre.org

Aliases: Zen

First seen
2013-01-01 00:00:00
Malware type
trojan, spyware
Family
Malware family
Operating systems
android
Related IoCs
5 (1 malicious)
Last IoC activity
2026-06-28 13:11:13
Profile updated
2026-07-07 14:21:10

Targeted industries: technology-and-telecommunications financial-services

Context

Zen is Android malware that was first seen in 2013.

Recent IoC activity

1 malicious indicator in Maltiverse are attributed to Zen (S0494). The 1 most recently updated:

TypeIndicatorUpdatedSources
file sample eb12cd65589cbc6f9d3563576c304273cb6a78072b0c20a155a0951370476d8d 2026-06-28 1

Malware & tools used

  • System Runtime API Hijacking (attack-pattern)
  • Exploitation for Privilege Escalation (attack-pattern)
  • Ptrace System Calls (attack-pattern)
  • Download New Code at Runtime (attack-pattern)
  • Obfuscated Files or Information (attack-pattern)
  • Disable or Modify Tools (attack-pattern)
  • Input Injection (attack-pattern)
  • Generate Traffic from Victim (attack-pattern)

Reports & references

  • security.googleblog.com — Pha Family Highlights Zen And Its (report)
  • MITRE ATT&CK — S0494 (report)

External references