FrozenCell
MITRE ATT&CK: S0577 View on attack.mitre.org
Aliases: FrozenCell
- Malware type
- spyware, rat
- Family
- Malware family
- Operating systems
- android
- Related IoCs
- 1 (1 malicious)
- Last IoC activity
- 2026-05-27 16:33:15
- Profile updated
- 2026-07-07 14:07:01
Targeted industries: government-and-public-sector media-and-entertainment
Targeted regions: country_code:ps country_code:sy
Context
FrozenCell is the mobile component of a family of surveillanceware, with a corresponding desktop component known as KasperAgent and Micropsia. There are multiple close variants of FrozenCell, such as VAMP, GnatSpy, Desert Scorpion and SpyC23, which add some additional functionality but are not significantly different from the original malware.
Recent IoC activity
1 malicious indicator in Maltiverse are attributed to FrozenCell (S0577). The 1 most recently updated:
| Type | Indicator | Updated | Sources |
|---|---|---|---|
| file sample | 220603-jb4d7ahaar.bin | 2026-05-27 | 1 |
Malware & tools used
- Location Tracking (attack-pattern)
- Data from Local System (attack-pattern)
- Download New Code at Runtime (attack-pattern)
- System Network Configuration Discovery (attack-pattern)
- File and Directory Discovery (attack-pattern)
- Match Legitimate Name or Location (attack-pattern)
- SMS Messages (attack-pattern)
- Stored Application Data (attack-pattern)
- System Information Discovery (attack-pattern)
- Archive Collected Data (attack-pattern)
- Audio Capture (attack-pattern)
Used by threat actors
- APT-C-23 (threat-actor)
Reports & references
- Trend Micro — New Gnatspy Mobile Malware Family Discovered (report)
- Palo Alto Unit 42 — Unit42 Targeted Attacks Middle East Using Kasperagent Micropsia (report)
- MITRE ATT&CK — S0577 (report)
- blog.lookout.com — Frozencell Mobile Threat (report)