TERRACOTTA

MITRE ATT&CK: S0545 View on attack.mitre.org

Aliases: TERRACOTTA

First seen
2019-07-01 00:00:00
Malware type
botnet
Family
Malware family
Operating systems
android
Profile updated
2026-07-07 15:31:26

Targeted industries: media-and-entertainment technology-and-telecommunications

Context

TERRACOTTA is an ad fraud botnet that has been capable of generating over 2 billion fraudulent requests per week.

Malware & tools used

  • Obfuscated Files or Information (attack-pattern)
  • Native API (attack-pattern)
  • Generate Traffic from Victim (attack-pattern)
  • GUI Input Capture (attack-pattern)
  • Internet Connection Discovery (attack-pattern)
  • Scheduled Task/Job (attack-pattern)
  • System Checks (attack-pattern)
  • Input Injection (attack-pattern)
  • Foreground Persistence (attack-pattern)
  • Broadcast Receivers (attack-pattern)
  • Software Discovery (attack-pattern)
  • Bidirectional Communication (attack-pattern)
  • System Network Configuration Discovery (attack-pattern)
  • Download New Code at Runtime (attack-pattern)
  • SMS Control (attack-pattern)

Reports & references

  • MITRE ATT&CK — S0545 (report)
  • whiteops.com — Terracotta Android Malware A Technical Study (report)

External references