SilkBean

MITRE ATT&CK: S0549 View on attack.mitre.org

Aliases: SilkBean

First seen
2019-05-01 00:00:00
Malware type
rat, spyware
Family
Malware family
Operating systems
android
Related IoCs
1 (1 malicious)
Last IoC activity
2026-07-01 09:14:22
Profile updated
2026-07-07 14:04:56

Targeted industries: government-and-public-sector

Targeted regions: country_code:cn

Context

SilkBean is a piece of Android surveillanceware containing comprehensive remote access tool (RAT) functionality that has been used in targeting of the Uyghur ethnic group.

Recent IoC activity

1 malicious indicator in Maltiverse are attributed to SilkBean (S0549). The 1 most recently updated:

TypeIndicatorUpdatedSources
file sample 0c4d8159034e7ba32d629d89c6a9dee2d813152bcbc1b875160531b0de9fbee5 2026-07-01 2

Malware & tools used

  • Contact List (attack-pattern)
  • Obfuscated Files or Information (attack-pattern)
  • Code Signing Policy Modification (attack-pattern)
  • SMS Control (attack-pattern)
  • Web Protocols (attack-pattern)
  • File and Directory Discovery (attack-pattern)
  • Video Capture (attack-pattern)
  • File Deletion (attack-pattern)
  • SMS Messages (attack-pattern)
  • Call Log (attack-pattern)
  • Download New Code at Runtime (attack-pattern)
  • Match Legitimate Name or Location (attack-pattern)
  • Asymmetric Cryptography (attack-pattern)
  • Location Tracking (attack-pattern)
  • Data from Local System (attack-pattern)

Reports & references

  • lookout.com — Lookout Uyghur Malware Tr Us (report)
  • malpedia.caad.fkie.fraunhofer.de — Apk.Silkbean (report)
  • MITRE ATT&CK — S0549 (report)

External references