CarbonSteal

MITRE ATT&CK: S0529 View on attack.mitre.org

Aliases: CarbonSteal

Malware type
spyware
Family
Malware family
Operating systems
android
Related IoCs
2 (2 malicious)
Last IoC activity
2026-04-24 07:34:00
Profile updated
2026-07-07 14:04:51

Targeted industries: government-and-public-sector technology-and-telecommunications media-and-entertainment education-and-nonprofits

Context

CarbonSteal is one of a family of four surveillanceware tools that share a common C2 infrastructure. CarbonSteal primarily deals with audio surveillance.

Recent IoC activity

2 malicious indicators in Maltiverse are attributed to CarbonSteal (S0529). The 2 most recently updated:

TypeIndicatorUpdatedSources
file sample 220124-d8vwesbdgq.bin 2026-04-24 1
file sample 220124-c4wfqaaegm.bin 2026-04-24 1

Malware & tools used

  • Asymmetric Cryptography (attack-pattern)
  • Software Discovery (attack-pattern)
  • Match Legitimate Name or Location (attack-pattern)
  • Native API (attack-pattern)
  • Call Control (attack-pattern)
  • Download New Code at Runtime (attack-pattern)
  • System Information Discovery (attack-pattern)
  • System Network Configuration Discovery (attack-pattern)
  • Location Tracking (attack-pattern)
  • Audio Capture (attack-pattern)
  • File and Directory Discovery (attack-pattern)
  • Stored Application Data (attack-pattern)
  • Obfuscated Files or Information (attack-pattern)
  • SMS Messages (attack-pattern)
  • Out of Band Data (attack-pattern)
  • Internet Connection Discovery (attack-pattern)
  • File Deletion (attack-pattern)

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Apk.Carbonsteal (report)
  • lookout.com — Lookout Uyghur Malware Tr Us (report)
  • MITRE ATT&CK — S0529 (report)

External references