Skip to content

S0303 MazarBOT

MazarBOT is Android malware that was distributed via SMS in Denmark in 2016. 1

Item Value
ID S0303
Associated Names
Version 1.1
Created 25 October 2017
Last Modified 11 December 2018
Navigation Layer View In ATT&CK® Navigator

Techniques Used

Domain ID Name Use
mobile T1412 Capture SMS Messages MazarBOT can intercept two-factor authentication codes sent by online banking apps.1
mobile T1448 Carrier Billing Fraud MazarBOT can send messages to premium-rate numbers.1
mobile T1476 Deliver Malicious App via Other Means MazarBOT is delivered via an unsolicited text message containing a link to a web download URI.1


Back to top