PINEFLOWER
- First seen
- 2023-01-15 00:00:00
- Malware type
- backdoor, spyware, trojan
- Family
- Malware family
- Profile updated
- 2026-07-07 13:08:58
Targeted industries: technology-and-telecommunications government-and-public-sector
Context
According to Mandiant, PINEFLOWER is an Android malware family capable of a wide range of backdoor functionality, including stealing system inform information, logging and recording phone calls, initiating audio recordings, reading SMS inboxes and sending SMS messages. The malware also has features to facilitate device location tracking, deleting, downloading, and uploading files, reading connectivity state, speed, and activity, and toggling Bluetooth, Wi-Fi, and mobile data settings.
Reports & references
- socradar.io — Dark Web Profile Apt42 Iranian Cyber Espionage Group (report)
- malpedia.caad.fkie.fraunhofer.de — Apk.Pineflower (report)
- Mandiant — 17826 (report)