Sunbird

MITRE ATT&CK: S1082 View on attack.mitre.org

Aliases: Sunbird

First seen
2017-01-01 00:00:00
Malware type
spyware
Family
Malware family
Operating systems
android
Related IoCs
1 (1 malicious)
Last IoC activity
2026-05-21 10:53:26
Profile updated
2026-07-07 15:30:04

Targeted industries: government-and-public-sector technology-and-telecommunications

Targeted regions: country_code:in country_code:pk

Context

Sunbird is one of two mobile malware families known to be used by the APT Confucius. Analysis suggests that Sunbird was first active in early 2017. While Sunbird and Hornbill overlap in core capabilities, Sunbird has a more extensive set of malicious features.

Recent IoC activity

1 malicious indicator in Maltiverse are attributed to Sunbird (S1082). The 1 most recently updated:

TypeIndicatorUpdatedSources
file sample 85d4eea8f2064fce43aae845d5685f300d1c93e52033df4e4e8b88e57a6abad2 2026-05-21 1

Malware & tools used

  • System Network Configuration Discovery (attack-pattern)
  • Unix Shell (attack-pattern)
  • Audio Capture (attack-pattern)
  • Screen Capture (attack-pattern)
  • Device Administrator Permissions (attack-pattern)
  • Data from Local System (attack-pattern)
  • System Information Discovery (attack-pattern)
  • Location Tracking (attack-pattern)
  • Call Log (attack-pattern)
  • Contact List (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)
  • Stored Application Data (attack-pattern)
  • Software Discovery (attack-pattern)
  • Exfiltration Over C2 Channel (attack-pattern)
  • Archive Collected Data (attack-pattern)
  • Video Capture (attack-pattern)
  • Calendar Entries (attack-pattern)

Used by threat actors

Reports & references

  • MITRE ATT&CK — S1082 (report)
  • lookout.com — Lookout Discovers Novel Confucius Apt Android Spyware Linked To India Pakistan Conflict (report)

External references