TianySpy

MITRE ATT&CK: S1056 View on attack.mitre.org

Aliases: TianySpy

First seen
2021-09-30 00:00:00
Malware type
credential-stealer, spyware
Family
Malware family
Operating systems
android, ios
Profile updated
2026-07-07 14:20:23

Targeted industries: technology-and-telecommunications

Targeted regions: country_code:jp

Context

TianySpy is a mobile malware primarily spread by SMS phishing between September 30 and October 12, 2021. TianySpy is believed to have targeted credentials associated with membership websites of major Japanese telecommunication services.

Malware & tools used

  • Code Signing Policy Modification (attack-pattern)
  • GUI Input Capture (attack-pattern)
  • Obfuscated Files or Information (attack-pattern)
  • System Information Discovery (attack-pattern)
  • Internet Connection Discovery (attack-pattern)
  • Exfiltration Over Alternative Protocol (attack-pattern)
  • Command and Scripting Interpreter (attack-pattern)
  • System Network Configuration Discovery (attack-pattern)
  • Wi-Fi Discovery (attack-pattern)

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Apk.Tianyspy (report)
  • Trend Micro — Tianyspy Malware Uses Smishing Disguised As Message From Telco (report)
  • MITRE ATT&CK — S1056 (report)

External references