VajraSpy
MITRE ATT&CK: S9006 View on attack.mitre.org
Aliases: VajraSpy
- First seen
- 2021-01-01 00:00:00
- Malware type
- spyware, trojan
- Family
- Malware family
- Operating systems
- android
- Related IoCs
- 1 (1 malicious)
- Last IoC activity
- 2026-07-17 15:55:09
- Profile updated
- 2026-07-07 14:20:47
Targeted industries: government-and-public-sector
Targeted regions: country_code:pk country_code:in
Context
VajraSpy is Android malware distributed via trojanized messaging and news applications. It has been used to target individuals in Pakistan and India since at least 2021 and has been delivered through the Google Play Store, malicious domains, and other uncontrolled distribution channels. VajraSpy is attributed with high confidence to Patchwork which has used the malware to conduct targeted espionage, primarily against devices in Pakistan.
Recent IoC activity
1 malicious indicator in Maltiverse are attributed to VajraSpy (S9006). The 1 most recently updated:
| Type | Indicator | Updated | Sources |
|---|---|---|---|
| file sample | c06f8c3fd23ae7124cc06eb63c0411418715bf99d3c9fa66525790b2b4c61858 | 2026-07-17 | 1 |
Malware & tools used
- Exfiltration Over Unencrypted Non-C2 Protocol (attack-pattern)
- Abuse Accessibility Features (attack-pattern)
- Call Log (attack-pattern)
- Audio Capture (attack-pattern)
- Location Tracking (attack-pattern)
- System Information Discovery (attack-pattern)
- Lockscreen Bypass (attack-pattern)
- File and Directory Discovery (attack-pattern)
- Accounts (attack-pattern)
- SMS Messages (attack-pattern)
- Access Notifications (attack-pattern)
- Wi-Fi Discovery (attack-pattern)
- Contact List (attack-pattern)
- Video Capture (attack-pattern)
- Stored Application Data (attack-pattern)
- Phishing (attack-pattern)
- Masquerading (attack-pattern)
- Bidirectional Communication (attack-pattern)
- Call Control (attack-pattern)
- Exfiltration Over C2 Channel (attack-pattern)
- Keylogging (attack-pattern)
- Software Discovery (attack-pattern)
- Data from Local System (attack-pattern)
Used by threat actors
- Patchwork (threat-actor)
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Apk.Vajraspy (report)
- mp.weixin.qq.com — B0Elrhbqlzs Wgqh79Ftww (report)
- twitter.com — 1509451238366236674 (report)
- twitter.com — 1481312752782258176 (report)
- arcticwolf.com — Dropping Elephant Apt Group Targets Turkish Defense Industry (report)
- MITRE ATT&CK — S9006 (report)
- labs.k7computing.com — Vajraspy An Android Rat (report)
- ESET — Vajraspy Patchwork Espionage Apps (report)