BusyGasper

MITRE ATT&CK: S0655 View on attack.mitre.org

Aliases: BusyGasper

First seen
2016-05-01 00:00:00
Malware type
spyware
Family
Malware family
Operating systems
android
Profile updated
2026-07-07 14:04:49

Targeted regions: country_code:ru

Context

BusyGasper is Android spyware that has been in use since May 2016. There have been less than 10 victims, all who appear to be located in Russia, that were all infected via physical access to the device.

Malware & tools used

  • Compromise Client Software Binary (attack-pattern)
  • Exfiltration Over Unencrypted Non-C2 Protocol (attack-pattern)
  • Bidirectional Communication (attack-pattern)
  • Data from Local System (attack-pattern)
  • Suppress Application Icon (attack-pattern)
  • Unix Shell (attack-pattern)
  • Keylogging (attack-pattern)
  • Audio Capture (attack-pattern)
  • Call Control (attack-pattern)
  • Video Capture (attack-pattern)
  • Download New Code at Runtime (attack-pattern)
  • Location Tracking (attack-pattern)
  • SMS Messages (attack-pattern)
  • User Evasion (attack-pattern)
  • SMS Control (attack-pattern)
  • Out of Band Data (attack-pattern)
  • Screen Capture (attack-pattern)
  • Stored Application Data (attack-pattern)

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Apk.Busygasper (report)
  • Kaspersky — 87627 (report)
  • MITRE ATT&CK — S0655 (report)

External references