Skip to content

S0426 Concipit1248

Concipit1248 is iOS spyware that was discovered using the same name as the developer of the Android spyware Corona Updates. Further investigation revealed that the two pieces of software contained the same C2 URL and similar functionality.1

Item Value
ID S0426
Associated Names Corona Updates
Version 1.0
Created 24 April 2020
Last Modified 30 April 2020
Navigation Layer View In ATT&CK® Navigator

Associated Software Descriptions

Name Description
Corona Updates 1

Techniques Used

Domain ID Name Use
mobile T1437 Application Layer Protocol -
mobile T1437.001 Web Protocols Concipit1248 communicates with the C2 server using HTTP requests.1
mobile T1533 Data from Local System Concipit1248 can collect device photos.1
mobile T1512 Video Capture Concipit1248 requests permissions to use the device camera.1