FlyTrap
MITRE ATT&CK: S1093 View on attack.mitre.org
Aliases: FlyTrap
- First seen
- 2021-03-01 00:00:00
- Malware type
- trojan, credential-stealer
- Family
- Malware family
- Operating systems
- android
- Related IoCs
- 3 (3 malicious)
- Last IoC activity
- 2026-08-26 09:18:46
- Profile updated
- 2026-07-07 14:06:36
Context
FlyTrap is an Android trojan, first detected in March 2021, that uses social engineering tactics to compromise Facebook accounts. FlyTrap was initially detected through infected apps on the Google Play store, and is believed to have impacted over 10,000 victims across at least 140 countries.
Recent IoC activity
3 malicious indicators in Maltiverse are attributed to FlyTrap (S1093). The 3 most recently updated:
| Type | Indicator | Updated | Sources |
|---|---|---|---|
| file sample | app-debug.apk | 2026-08-26 | 1 |
| file sample | app-debug.apk | 2026-04-22 | 1 |
| file sample | rednote-9-27-0.apk | 2026-04-20 | 1 |
Malware & tools used
- Web Protocols (attack-pattern)
- Internet Connection Discovery (attack-pattern)
- Stored Application Data (attack-pattern)
- Location Tracking (attack-pattern)
- Exfiltration Over C2 Channel (attack-pattern)
- GUI Input Capture (attack-pattern)
- System Network Configuration Discovery (attack-pattern)
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Apk.Flytrap (report)
- blog.zimperium.com — Flytrap Android Malware Compromises Thousands Of Facebook Accounts (report)
- MITRE ATT&CK — S1093 (report)
- Trend Micro — Flytrap Android Malware Is Taking Over Facebook Accounts Protect Yourself With A Malware Scanner (report)