CherryBlos

MITRE ATT&CK: S1225 View on attack.mitre.org

Aliases: CherryBlos

First seen
2023-04-01 00:00:00
Malware type
credential-stealer, cryptominer
Family
Malware family
Operating systems
android
Profile updated
2026-07-07 15:31:52

Targeted industries: financial-services

Targeted regions: country_code:my country_code:vn country_code:id country_code:ph country_code:ug country_code:mx

Context

CherryBlos is an Android malware that steals credentials and redirects cryptocurrency to adversary-controlled wallets. CherryBlos was labelled Robot 999 in its first appearance in April 2023; since then, various aliases have been used, including GPTalk, Happy Miner, and SynthNet. The threat actors behind CherryBlos uploaded the malware to different Google Play regions, such as Malaysia, Vietnam, Indonesia, Philippines, Uganda, and Mexico.

Malware & tools used

  • Foreground Persistence (attack-pattern)
  • Abuse Accessibility Features (attack-pattern)
  • Input Capture (attack-pattern)
  • Process Discovery (attack-pattern)
  • Software Discovery (attack-pattern)
  • Phishing (attack-pattern)
  • File and Directory Discovery (attack-pattern)
  • Impair Defenses (attack-pattern)
  • Exfiltration Over C2 Channel (attack-pattern)
  • Software Packing (attack-pattern)
  • Masquerading (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)
  • Web Protocols (attack-pattern)

Reports & references

  • MITRE ATT&CK — S1225 (report)
  • Trend Micro — Cherryblos And Faketrade Android Malware Involved In Scam Campai (report)

External references