FlyTrap

MITRE ATT&CK: S1093 View on attack.mitre.org

Aliases: FlyTrap

First seen
2021-03-01 00:00:00
Malware type
trojan, credential-stealer
Family
Malware family
Operating systems
android
Related IoCs
3 (3 malicious)
Last IoC activity
2026-08-26 09:18:46
Profile updated
2026-07-07 14:06:36

Context

FlyTrap is an Android trojan, first detected in March 2021, that uses social engineering tactics to compromise Facebook accounts. FlyTrap was initially detected through infected apps on the Google Play store, and is believed to have impacted over 10,000 victims across at least 140 countries.

Recent IoC activity

3 malicious indicators in Maltiverse are attributed to FlyTrap (S1093). The 3 most recently updated:

TypeIndicatorUpdatedSources
file sample app-debug.apk 2026-08-26 1
file sample app-debug.apk 2026-04-22 1
file sample rednote-9-27-0.apk 2026-04-20 1

Malware & tools used

  • Web Protocols (attack-pattern)
  • Internet Connection Discovery (attack-pattern)
  • Stored Application Data (attack-pattern)
  • Location Tracking (attack-pattern)
  • Exfiltration Over C2 Channel (attack-pattern)
  • GUI Input Capture (attack-pattern)
  • System Network Configuration Discovery (attack-pattern)

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Apk.Flytrap (report)
  • blog.zimperium.com — Flytrap Android Malware Compromises Thousands Of Facebook Accounts (report)
  • MITRE ATT&CK — S1093 (report)
  • Trend Micro — Flytrap Android Malware Is Taking Over Facebook Accounts Protect Yourself With A Malware Scanner (report)

External references