Sunbird
MITRE ATT&CK: S1082 View on attack.mitre.org
Aliases: Sunbird
- First seen
- 2017-01-01 00:00:00
- Malware type
- spyware
- Family
- Malware family
- Operating systems
- android
- Related IoCs
- 1 (1 malicious)
- Last IoC activity
- 2026-05-21 10:53:26
- Profile updated
- 2026-07-07 15:30:04
Targeted industries: government-and-public-sector technology-and-telecommunications
Targeted regions: country_code:in country_code:pk
Context
Sunbird is one of two mobile malware families known to be used by the APT Confucius. Analysis suggests that Sunbird was first active in early 2017. While Sunbird and Hornbill overlap in core capabilities, Sunbird has a more extensive set of malicious features.
Recent IoC activity
1 malicious indicator in Maltiverse are attributed to Sunbird (S1082). The 1 most recently updated:
| Type | Indicator | Updated | Sources |
|---|---|---|---|
| file sample | 85d4eea8f2064fce43aae845d5685f300d1c93e52033df4e4e8b88e57a6abad2 | 2026-05-21 | 1 |
Malware & tools used
- System Network Configuration Discovery (attack-pattern)
- Unix Shell (attack-pattern)
- Audio Capture (attack-pattern)
- Screen Capture (attack-pattern)
- Device Administrator Permissions (attack-pattern)
- Data from Local System (attack-pattern)
- System Information Discovery (attack-pattern)
- Location Tracking (attack-pattern)
- Call Log (attack-pattern)
- Contact List (attack-pattern)
- Ingress Tool Transfer (attack-pattern)
- Stored Application Data (attack-pattern)
- Software Discovery (attack-pattern)
- Exfiltration Over C2 Channel (attack-pattern)
- Archive Collected Data (attack-pattern)
- Video Capture (attack-pattern)
- Calendar Entries (attack-pattern)
Used by threat actors
- Confucius (threat-actor)
Reports & references
- MITRE ATT&CK — S1082 (report)
- lookout.com — Lookout Discovers Novel Confucius Apt Android Spyware Linked To India Pakistan Conflict (report)