TangleBot

MITRE ATT&CK: S1069 View on attack.mitre.org

Aliases: TangleBot

First seen
2021-09-01 00:00:00
Malware type
trojan, spyware
Family
Malware family
Operating systems
android
Related IoCs
14 (13 malicious)
Last IoC activity
2026-08-18 21:24:29
Profile updated
2026-07-07 14:08:24

Targeted industries: healthcare-and-pharmaceutical

Targeted regions: country_code:us country_code:ca

Context

TangleBot is SMS malware that was initially observed in September 2021, primarily targeting mobile users in the United States and Canada. TangleBot has used SMS text message lures about COVID-19 regulations and vaccines to trick mobile users into downloading the malware, similar to FluBot Android malware campaigns.

Recent IoC activity

13 malicious indicators in Maltiverse are attributed to TangleBot (S1069). The 13 most recently updated:

Malware & tools used

  • Software Discovery (attack-pattern)
  • Location Tracking (attack-pattern)
  • Video Capture (attack-pattern)
  • Contact List (attack-pattern)
  • Data from Local System (attack-pattern)
  • Call Control (attack-pattern)
  • GUI Input Capture (attack-pattern)
  • Audio Capture (attack-pattern)
  • SMS Messages (attack-pattern)
  • Screen Capture (attack-pattern)
  • SMS Control (attack-pattern)
  • Call Log (attack-pattern)

Reports & references

  • cleafy.com — Medusa Reborn A New Compact Variant Discovered (report)
  • malpedia.caad.fkie.fraunhofer.de — Apk.Tangle Bot (report)
  • proofpoint.com — Mobile Malware Tanglebot Untangled (report)
  • MITRE ATT&CK — S1069 (report)
  • cloudmark.com — Tanglebot New Advanced Sms Malware Targets Mobile Users Across Us And Canada Covid 19 (report)

External references