CarbonSteal
MITRE ATT&CK: S0529 View on attack.mitre.org
Aliases: CarbonSteal
- Malware type
- spyware
- Family
- Malware family
- Operating systems
- android
- Related IoCs
- 2 (2 malicious)
- Last IoC activity
- 2026-04-24 07:34:00
- Profile updated
- 2026-07-07 14:04:51
Targeted industries: government-and-public-sector technology-and-telecommunications media-and-entertainment education-and-nonprofits
Context
CarbonSteal is one of a family of four surveillanceware tools that share a common C2 infrastructure. CarbonSteal primarily deals with audio surveillance.
Recent IoC activity
2 malicious indicators in Maltiverse are attributed to CarbonSteal (S0529). The 2 most recently updated:
| Type | Indicator | Updated | Sources |
|---|---|---|---|
| file sample | 220124-d8vwesbdgq.bin | 2026-04-24 | 1 |
| file sample | 220124-c4wfqaaegm.bin | 2026-04-24 | 1 |
Malware & tools used
- Asymmetric Cryptography (attack-pattern)
- Software Discovery (attack-pattern)
- Match Legitimate Name or Location (attack-pattern)
- Native API (attack-pattern)
- Call Control (attack-pattern)
- Download New Code at Runtime (attack-pattern)
- System Information Discovery (attack-pattern)
- System Network Configuration Discovery (attack-pattern)
- Location Tracking (attack-pattern)
- Audio Capture (attack-pattern)
- File and Directory Discovery (attack-pattern)
- Stored Application Data (attack-pattern)
- Obfuscated Files or Information (attack-pattern)
- SMS Messages (attack-pattern)
- Out of Band Data (attack-pattern)
- Internet Connection Discovery (attack-pattern)
- File Deletion (attack-pattern)
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Apk.Carbonsteal (report)
- lookout.com — Lookout Uyghur Malware Tr Us (report)
- MITRE ATT&CK — S0529 (report)