PINEFLOWER

First seen
2023-01-15 00:00:00
Malware type
backdoor, spyware, trojan
Family
Malware family
Profile updated
2026-07-07 13:08:58

Targeted industries: technology-and-telecommunications government-and-public-sector

Context

According to Mandiant, PINEFLOWER is an Android malware family capable of a wide range of backdoor functionality, including stealing system inform information, logging and recording phone calls, initiating audio recordings, reading SMS inboxes and sending SMS messages. The malware also has features to facilitate device location tracking, deleting, downloading, and uploading files, reading connectivity state, speed, and activity, and toggling Bluetooth, Wi-Fi, and mobile data settings.

Reports & references

  • socradar.io — Dark Web Profile Apt42 Iranian Cyber Espionage Group (report)
  • malpedia.caad.fkie.fraunhofer.de — Apk.Pineflower (report)
  • Mandiant — 17826 (report)

External references