Android/SpyAgent
MITRE ATT&CK: S1214 View on attack.mitre.org
Aliases: Android/SpyAgent
- First seen
- 2019-05-01 00:00:00
- Malware type
- spyware
- Family
- Malware family
- Operating systems
- android
- Profile updated
- 2026-07-07 15:28:50
Targeted industries: government-and-public-sector technology-and-telecommunications
Targeted regions: country_code:kr country_code:jp
Context
Android/SpyAgent is a variant of spyware in the MoqHao phishing campaign primarily targeting Korean and Japanese users. Fake security applications were used to target Japanese users, while fake police applications were used to target Korean users. Both fake applications have common C2 commands and share the same crash report key on a cloud service.
Malware & tools used
- Disable or Modify Tools (attack-pattern)
- Match Legitimate Name or Location (attack-pattern)
- Web Service (attack-pattern)
- SMS Messages (attack-pattern)
- Call Control (attack-pattern)
- Dead Drop Resolver (attack-pattern)
- System Network Configuration Discovery (attack-pattern)
- Obfuscated Files or Information (attack-pattern)
Reports & references
- MITRE ATT&CK — S1214 (report)
- McAfee — Moqhao Related Android Spyware Targeting Japan And Korea Found On Google Play (report)