mobile |
T1433 |
Access Call Log |
GolfSpy can obtain the device’s call log. |
mobile |
T1432 |
Access Contact List |
GolfSpy can obtain the device’s contact list. |
mobile |
T1418 |
Application Discovery |
GolfSpy can obtain a list of installed applications. |
mobile |
T1402 |
Broadcast Receivers |
GolfSpy registers for the USER_PRESENT broadcast intent and uses it as a trigger to take photos with the front-facing camera. |
mobile |
T1429 |
Capture Audio |
GolfSpy can record audio and phone calls. |
mobile |
T1512 |
Capture Camera |
GolfSpy can record video. |
mobile |
T1414 |
Capture Clipboard Data |
GolfSpy can obtain clipboard contents. |
mobile |
T1412 |
Capture SMS Messages |
GolfSpy can collect SMS messages. |
mobile |
T1532 |
Data Encrypted |
GolfSpy encrypts data using a simple XOR operation with a pre-configured key prior to exfiltration. |
mobile |
T1533 |
Data from Local System |
GolfSpy can collect local accounts on the device, pictures, bookmarks/histories of the default browser, and files stored on the SD card. GolfSpy can list image, audio, video, and other files stored on the device. GolfSpy can copy arbitrary files from the device. |
mobile |
T1447 |
Delete Device Data |
GolfSpy can delete arbitrary files on the device. |
mobile |
T1476 |
Deliver Malicious App via Other Means |
GolfSpy can install attacker-specified applications. |
mobile |
T1430 |
Location Tracking |
GolfSpy can track the device’s location. |
mobile |
T1406 |
Obfuscated Files or Information |
GolfSpy encodes its configurations using a customized algorithm. |
mobile |
T1424 |
Process Discovery |
GolfSpy can obtain a list of running processes. |
mobile |
T1513 |
Screen Capture |
GolfSpy can take screenshots. |
mobile |
T1437 |
Standard Application Layer Protocol |
GolfSpy exfiltrates data using HTTP POST requests. |
mobile |
T1426 |
System Information Discovery |
GolfSpy can obtain the device’s battery level, network operator, connection information, sensor information, and information about the device’s storage and memory. |