AbstractEmu

MITRE ATT&CK: S1061 View on attack.mitre.org

Aliases: AbstractEmu

First seen
2021-10-01 00:00:00
Malware type
rootkit, trojan
Family
Malware family
Operating systems
android
Profile updated
2026-07-07 14:03:07

Targeted industries: technology-and-telecommunications retail-and-hospitality

Targeted regions: country_code:us

Context

AbstractEmu is mobile malware that was first seen in Google Play and other third-party stores in October 2021. It was discovered in 19 Android applications, of which at least 7 abused known Android exploits for obtaining root permissions. AbstractEmu was observed primarily impacting users in the United States, however victims are believed to be across a total of 17 countries.

Malware & tools used

  • Access Notifications (attack-pattern)
  • System Checks (attack-pattern)
  • Unix Shell (attack-pattern)
  • Obfuscated Files or Information (attack-pattern)
  • Internet Connection Discovery (attack-pattern)
  • System Network Configuration Discovery (attack-pattern)
  • Virtualization/Sandbox Evasion (attack-pattern)
  • Exploitation for Privilege Escalation (attack-pattern)
  • Web Protocols (attack-pattern)
  • SMS Messages (attack-pattern)
  • Audio Capture (attack-pattern)
  • Exfiltration Over C2 Channel (attack-pattern)
  • Disable or Modify Tools (attack-pattern)
  • Software Discovery (attack-pattern)
  • System Information Discovery (attack-pattern)
  • Data from Local System (attack-pattern)
  • Video Capture (attack-pattern)
  • Call Log (attack-pattern)
  • Location Tracking (attack-pattern)
  • Device Administrator Permissions (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)
  • Download New Code at Runtime (attack-pattern)
  • Contact List (attack-pattern)

Reports & references

  • blogs.blackberry.com — Dot Net Stubs Sowing The Seeds Of Discord (report)
  • malpedia.caad.fkie.fraunhofer.de — Apk.Abstract Emu (report)
  • blog.lookout.com — Lookout Discovers Global Rooting Malware Campaign (report)
  • sentinelone.com — The Art And Science Of Macos Malware Hunting With Radare2 Leveraging Xrefs Yara And Zignatures (report)
  • MITRE ATT&CK — S1061 (report)
  • lookout.com — Lookout Discovers Global Rooting Malware Campaign (report)

External references