VajraSpy

MITRE ATT&CK: S9006 View on attack.mitre.org

Aliases: VajraSpy

First seen
2021-01-01 00:00:00
Malware type
spyware, trojan
Family
Malware family
Operating systems
android
Related IoCs
1 (1 malicious)
Last IoC activity
2026-07-17 15:55:09
Profile updated
2026-07-07 14:20:47

Targeted industries: government-and-public-sector

Targeted regions: country_code:pk country_code:in

Context

VajraSpy is Android malware distributed via trojanized messaging and news applications. It has been used to target individuals in Pakistan and India since at least 2021 and has been delivered through the Google Play Store, malicious domains, and other uncontrolled distribution channels. VajraSpy is attributed with high confidence to Patchwork which has used the malware to conduct targeted espionage, primarily against devices in Pakistan.

Recent IoC activity

1 malicious indicator in Maltiverse are attributed to VajraSpy (S9006). The 1 most recently updated:

TypeIndicatorUpdatedSources
file sample c06f8c3fd23ae7124cc06eb63c0411418715bf99d3c9fa66525790b2b4c61858 2026-07-17 1

Malware & tools used

  • Exfiltration Over Unencrypted Non-C2 Protocol (attack-pattern)
  • Abuse Accessibility Features (attack-pattern)
  • Call Log (attack-pattern)
  • Audio Capture (attack-pattern)
  • Location Tracking (attack-pattern)
  • System Information Discovery (attack-pattern)
  • Lockscreen Bypass (attack-pattern)
  • File and Directory Discovery (attack-pattern)
  • Accounts (attack-pattern)
  • SMS Messages (attack-pattern)
  • Access Notifications (attack-pattern)
  • Wi-Fi Discovery (attack-pattern)
  • Contact List (attack-pattern)
  • Video Capture (attack-pattern)
  • Stored Application Data (attack-pattern)
  • Phishing (attack-pattern)
  • Masquerading (attack-pattern)
  • Bidirectional Communication (attack-pattern)
  • Call Control (attack-pattern)
  • Exfiltration Over C2 Channel (attack-pattern)
  • Keylogging (attack-pattern)
  • Software Discovery (attack-pattern)
  • Data from Local System (attack-pattern)

Used by threat actors

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Apk.Vajraspy (report)
  • mp.weixin.qq.com — B0Elrhbqlzs Wgqh79Ftww (report)
  • twitter.com — 1509451238366236674 (report)
  • twitter.com — 1481312752782258176 (report)
  • arcticwolf.com — Dropping Elephant Apt Group Targets Turkish Defense Industry (report)
  • MITRE ATT&CK — S9006 (report)
  • labs.k7computing.com — Vajraspy An Android Rat (report)
  • ESET — Vajraspy Patchwork Espionage Apps (report)

External references