FjordPhantom

MITRE ATT&CK: S1208 View on attack.mitre.org

Aliases: FjordPhantom

Malware type
trojan, spyware
Family
Malware family
Operating systems
android
Profile updated
2026-07-07 15:30:01

Targeted industries: financial-services

Targeted regions: country_code:id country_code:th country_code:vn

Context

FjordPhantom is a malicious Android application first discovered in September 2024 with targets in Southeast Asia, specifically Indonesia, Thailand, and Vietnam. FjordPhantom was distributed through email and messaging applications. Once installed, the application launches a virtualization solution to steal important information, such as bank accounts, and to manipulate the user interface. The malicious activity from the virtualization solution runs alongside legitimate banking applications.

Malware & tools used

  • Virtualization Solution (attack-pattern)
  • Process Injection (attack-pattern)
  • Masquerading (attack-pattern)
  • Phishing (attack-pattern)
  • Hooking (attack-pattern)

Reports & references

  • MITRE ATT&CK — S1208 (report)
  • promon.io — Fjordphantom Android Malware (report)

External references