Skip to content

S0303 MazarBOT

MazarBOT is Android malware that was distributed via SMS in Denmark in 2016. 1

Item Value
ID S0303
Version 1.0
Created 25 October 2017
Last Modified 24 October 2022
Navigation Layer View In ATT&CK® Navigator

Techniques Used

Domain ID Name Use
mobile T1643 Generate Traffic from Victim MazarBOT can send messages to premium-rate numbers.1
mobile T1636 Protected User Data -
mobile T1636.004 SMS Messages MazarBOT can intercept two-factor authentication codes sent by online banking apps.1