HenBox
MITRE ATT&CK: S0544 View on attack.mitre.org
Aliases: HenBox
- Malware type
- spyware, trojan
- Family
- Malware family
- Operating systems
- android
- Related IoCs
- 1 (1 malicious)
- Last IoC activity
- 2026-05-08 12:00:22
- Profile updated
- 2026-07-07 14:07:44
Targeted regions: country_code:cn
Context
HenBox is Android malware that attempts to only execute on Xiaomi devices running the MIUI operating system. HenBox has primarily been used to target Uyghurs, a minority Turkic ethnic group.
Recent IoC activity
1 malicious indicator in Maltiverse are attributed to HenBox (S0544). The 1 most recently updated:
| Type | Indicator | Updated | Sources |
|---|---|---|---|
| file sample | a6c7351b09a733a1b3ff8a0901c5bdefdc3b566bfcedcdf5a338c3a97c9f249b | 2026-05-08 | 1 |
Malware & tools used
- Call Log (attack-pattern)
- SMS Messages (attack-pattern)
- System Checks (attack-pattern)
- Unix Shell (attack-pattern)
- Native API (attack-pattern)
- Software Discovery (attack-pattern)
- Obfuscated Files or Information (attack-pattern)
- Broadcast Receivers (attack-pattern)
- Match Legitimate Name or Location (attack-pattern)
- Audio Capture (attack-pattern)
- Data from Local System (attack-pattern)
- System Information Discovery (attack-pattern)
- Process Discovery (attack-pattern)
- Video Capture (attack-pattern)
- Location Tracking (attack-pattern)
- Contact List (attack-pattern)
- Download New Code at Runtime (attack-pattern)
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Apk.Henbox (report)
- Palo Alto Unit 42 — Unit42 Henbox Chickens Come Home Roost (report)
- Palo Alto Unit 42 — Pkplug Chinese Cyber Espionage Group Attacking Asia (report)
- virusbulletin.com — Vb2019 Paper Pulling Pkplug Adversary Playbook Long Standing Espionage Activity Chinese Nation State Adversary (report)
- MITRE ATT&CK — S0544 (report)