CherryBlos
MITRE ATT&CK: S1225 View on attack.mitre.org
Aliases: CherryBlos
- First seen
- 2023-04-01 00:00:00
- Malware type
- credential-stealer, cryptominer
- Family
- Malware family
- Operating systems
- android
- Profile updated
- 2026-07-07 15:31:52
Targeted industries: financial-services
Targeted regions: country_code:my country_code:vn country_code:id country_code:ph country_code:ug country_code:mx
Context
CherryBlos is an Android malware that steals credentials and redirects cryptocurrency to adversary-controlled wallets. CherryBlos was labelled Robot 999 in its first appearance in April 2023; since then, various aliases have been used, including GPTalk, Happy Miner, and SynthNet. The threat actors behind CherryBlos uploaded the malware to different Google Play regions, such as Malaysia, Vietnam, Indonesia, Philippines, Uganda, and Mexico.
Malware & tools used
- Foreground Persistence (attack-pattern)
- Abuse Accessibility Features (attack-pattern)
- Input Capture (attack-pattern)
- Process Discovery (attack-pattern)
- Software Discovery (attack-pattern)
- Phishing (attack-pattern)
- File and Directory Discovery (attack-pattern)
- Impair Defenses (attack-pattern)
- Exfiltration Over C2 Channel (attack-pattern)
- Software Packing (attack-pattern)
- Masquerading (attack-pattern)
- Ingress Tool Transfer (attack-pattern)
- Web Protocols (attack-pattern)
Reports & references
- MITRE ATT&CK — S1225 (report)
- Trend Micro — Cherryblos And Faketrade Android Malware Involved In Scam Campai (report)