mobile |
T1437 |
Application Layer Protocol |
- |
mobile |
T1437.001 |
Web Protocols |
Exodus One checks in with the command and control server using HTTP POST requests. |
mobile |
T1532 |
Archive Collected Data |
Exodus One encrypts data using XOR prior to exfiltration. |
mobile |
T1429 |
Audio Capture |
Exodus Two can record audio from the compromised device’s microphone and can record call audio in 3GP format. |
mobile |
T1533 |
Data from Local System |
Exodus Two can extract information on pictures from the Gallery, Chrome and SBrowser bookmarks, and the connected WiFi network’s password. |
mobile |
T1407 |
Download New Code at Runtime |
Exodus One, after checking in, sends a POST request and then downloads Exodus Two, the second stage binaries. |
mobile |
T1404 |
Exploitation for Privilege Escalation |
Exodus Two attempts to elevate privileges by using a modified version of the DirtyCow exploit. |
mobile |
T1430 |
Location Tracking |
Exodus Two can extract the GPS coordinates of the device. |
mobile |
T1509 |
Non-Standard Port |
Exodus Two attempts to connect to port 22011 to provide a remote reverse shell. |
mobile |
T1636 |
Protected User Data |
- |
mobile |
T1636.001 |
Calendar Entries |
Exodus Two can exfiltrate calendar events. |
mobile |
T1636.002 |
Call Log |
Exodus Two can exfiltrate the call log. |
mobile |
T1636.003 |
Contact List |
Exodus Two can download the address book. |
mobile |
T1636.004 |
SMS Messages |
Exodus Two can capture SMS messages. |
mobile |
T1513 |
Screen Capture |
Exodus Two can take screenshots of any application in the foreground. |
mobile |
T1418 |
Software Discovery |
Exodus Two can obtain a list of installed applications. |
mobile |
T1409 |
Stored Application Data |
Exodus Two extracts information from Facebook, Facebook Messenger, Gmail, IMO, Skype, Telegram, Viber, WhatsApp, and WeChat. |
mobile |
T1422 |
System Network Configuration Discovery |
Exodus One queries the device for its IMEI code and the phone number in order to validate the target of a new infection. |
mobile |
T1421 |
System Network Connections Discovery |
Exodus Two collects a list of nearby base stations. |
mobile |
T1512 |
Video Capture |
Exodus Two can take pictures with the device cameras. |