TangleBot
MITRE ATT&CK: S1069 View on attack.mitre.org
Aliases: TangleBot
- First seen
- 2021-09-01 00:00:00
- Malware type
- trojan, spyware
- Family
- Malware family
- Operating systems
- android
- Related IoCs
- 14 (13 malicious)
- Last IoC activity
- 2026-08-18 21:24:29
- Profile updated
- 2026-07-07 14:08:24
Targeted industries: healthcare-and-pharmaceutical
Targeted regions: country_code:us country_code:ca
Context
TangleBot is SMS malware that was initially observed in September 2021, primarily targeting mobile users in the United States and Canada. TangleBot has used SMS text message lures about COVID-19 regulations and vaccines to trick mobile users into downloading the malware, similar to FluBot Android malware campaigns.
Recent IoC activity
13 malicious indicators in Maltiverse are attributed to TangleBot (S1069). The 13 most recently updated:
Malware & tools used
- Software Discovery (attack-pattern)
- Location Tracking (attack-pattern)
- Video Capture (attack-pattern)
- Contact List (attack-pattern)
- Data from Local System (attack-pattern)
- Call Control (attack-pattern)
- GUI Input Capture (attack-pattern)
- Audio Capture (attack-pattern)
- SMS Messages (attack-pattern)
- Screen Capture (attack-pattern)
- SMS Control (attack-pattern)
- Call Log (attack-pattern)
Reports & references
- cleafy.com — Medusa Reborn A New Compact Variant Discovered (report)
- malpedia.caad.fkie.fraunhofer.de — Apk.Tangle Bot (report)
- proofpoint.com — Mobile Malware Tanglebot Untangled (report)
- MITRE ATT&CK — S1069 (report)
- cloudmark.com — Tanglebot New Advanced Sms Malware Targets Mobile Users Across Us And Canada Covid 19 (report)