BOULDSPY

MITRE ATT&CK: S1079 View on attack.mitre.org

Aliases: BOULDSPY

First seen
2023-01-01 00:00:00
Malware type
spyware, rat
Family
Malware family
Operating systems
android
Profile updated
2026-07-07 14:05:38

Targeted industries: government-and-public-sector education-and-nonprofits

Targeted regions: country_code:ir

Context

BOULDSPY is an Android malware, detected in early 2023, with surveillance and remote-control capabilities. Analysis of exfiltrated C2 data suggests that BOULDSPY primarily targeted minority groups in Iran.

Malware & tools used

  • Stored Application Data (attack-pattern)
  • Archive Collected Data (attack-pattern)
  • Download New Code at Runtime (attack-pattern)
  • Audio Capture (attack-pattern)
  • Contact List (attack-pattern)
  • Wi-Fi Discovery (attack-pattern)
  • Clipboard Data (attack-pattern)
  • System Network Configuration Discovery (attack-pattern)
  • Exfiltration Over C2 Channel (attack-pattern)
  • Screen Capture (attack-pattern)
  • Web Protocols (attack-pattern)
  • Data from Local System (attack-pattern)
  • System Information Discovery (attack-pattern)
  • Match Legitimate Name or Location (attack-pattern)
  • Out of Band Data (attack-pattern)
  • Call Log (attack-pattern)
  • Video Capture (attack-pattern)
  • Keylogging (attack-pattern)
  • Compromise Application Executable (attack-pattern)
  • SMS Messages (attack-pattern)
  • Software Discovery (attack-pattern)
  • Internet Connection Discovery (attack-pattern)
  • Boot or Logon Initialization Scripts (attack-pattern)
  • Event Triggered Execution (attack-pattern)
  • Location Tracking (attack-pattern)

Reports & references

  • lookout.com — Iranian Spyware Bouldspy (report)
  • MITRE ATT&CK — S1079 (report)

External references