Hornbill
MITRE ATT&CK: S1077 View on attack.mitre.org
Aliases: Hornbill
- First seen
- 2018-01-01 00:00:00
- Malware type
- spyware
- Family
- Malware family
- Operating systems
- android
- Related IoCs
- 1 (1 malicious)
- Last IoC activity
- 2026-05-21 06:48:33
- Profile updated
- 2026-07-07 15:30:06
Targeted industries: government-and-public-sector defense-and-aerospace
Targeted regions: country_code:bh country_code:in country_code:pk
Context
Hornbill is one of two mobile malware families known to be used by the APT Confucius. Analysis suggests that Hornbill was first active in early 2018. While Hornbill and Sunbird overlap in core capabilities, Hornbill has tools and behaviors suggesting more passive reconnaissance.
Recent IoC activity
1 malicious indicator in Maltiverse are attributed to Hornbill (S1077). The 1 most recently updated:
| Type | Indicator | Updated | Sources |
|---|---|---|---|
| file sample | 6ca7fda71126ce64d3263e6e1471eda0921ce3796e71f89e40c1073fcc81a213 | 2026-05-21 | 1 |
Malware & tools used
- System Network Configuration Discovery (attack-pattern)
- Contact List (attack-pattern)
- File Deletion (attack-pattern)
- User Evasion (attack-pattern)
- Match Legitimate Name or Location (attack-pattern)
- Audio Capture (attack-pattern)
- Web Protocols (attack-pattern)
- System Information Discovery (attack-pattern)
- Location Tracking (attack-pattern)
- Exfiltration Over C2 Channel (attack-pattern)
- Access Notifications (attack-pattern)
- File and Directory Discovery (attack-pattern)
- Software Discovery (attack-pattern)
- Stored Application Data (attack-pattern)
- Screen Capture (attack-pattern)
- Data from Local System (attack-pattern)
- Call Log (attack-pattern)
- Internet Connection Discovery (attack-pattern)
- Device Administrator Permissions (attack-pattern)
- Wi-Fi Discovery (attack-pattern)
- Video Capture (attack-pattern)
Used by threat actors
- Confucius (threat-actor)
Reports & references
- lookout.com — Lookout Discovers Novel Confucius Apt Android Spyware Linked To India Pakistan Conflict (report)
- MITRE ATT&CK — S1077 (report)