DoubleAgent
MITRE ATT&CK: S0550 View on attack.mitre.org
Aliases: DoubleAgent
- First seen
- 2013-01-01 00:00:00
- Malware type
- rat
- Family
- Malware family
- Operating systems
- android
- Last IoC activity
- 2026-05-27 16:57:51
- Profile updated
- 2026-07-07 14:04:55
Targeted industries: government-and-public-sector technology-and-telecommunications defense-and-aerospace
Context
DoubleAgent is a family of RAT malware dating back to 2013, known to target groups with contentious relationships with the Chinese government.
Malware & tools used
- Suppress Application Icon (attack-pattern)
- Contact List (attack-pattern)
- SMS Messages (attack-pattern)
- Compromise Client Software Binary (attack-pattern)
- Unix Shell (attack-pattern)
- Audio Capture (attack-pattern)
- Download New Code at Runtime (attack-pattern)
- Call Log (attack-pattern)
- File Deletion (attack-pattern)
- Data from Local System (attack-pattern)
- Application Layer Protocol (attack-pattern)
- Exploitation for Privilege Escalation (attack-pattern)
- Obfuscated Files or Information (attack-pattern)
- Stored Application Data (attack-pattern)
- File and Directory Discovery (attack-pattern)
- Software Discovery (attack-pattern)
- Match Legitimate Name or Location (attack-pattern)
- System Information Discovery (attack-pattern)
Reports & references
- lookout.com — Lookout Uyghur Malware Tr Us (report)
- malpedia.caad.fkie.fraunhofer.de — Apk.Doubleagent (report)
- MITRE ATT&CK — S0550 (report)