Android/SpyAgent

MITRE ATT&CK: S1214 View on attack.mitre.org

Aliases: Android/SpyAgent

First seen
2019-05-01 00:00:00
Malware type
spyware
Family
Malware family
Operating systems
android
Profile updated
2026-07-07 15:28:50

Targeted industries: government-and-public-sector technology-and-telecommunications

Targeted regions: country_code:kr country_code:jp

Context

Android/SpyAgent is a variant of spyware in the MoqHao phishing campaign primarily targeting Korean and Japanese users. Fake security applications were used to target Japanese users, while fake police applications were used to target Korean users. Both fake applications have common C2 commands and share the same crash report key on a cloud service.

Malware & tools used

  • Disable or Modify Tools (attack-pattern)
  • Match Legitimate Name or Location (attack-pattern)
  • Web Service (attack-pattern)
  • SMS Messages (attack-pattern)
  • Call Control (attack-pattern)
  • Dead Drop Resolver (attack-pattern)
  • System Network Configuration Discovery (attack-pattern)
  • Obfuscated Files or Information (attack-pattern)

Reports & references

  • MITRE ATT&CK — S1214 (report)
  • McAfee — Moqhao Related Android Spyware Targeting Japan And Korea Found On Google Play (report)

External references