| mobile |
T1437 |
Application Layer Protocol |
- |
| mobile |
T1437.001 |
Web Protocols |
FakeSpy exfiltrates data using HTTP requests. |
| mobile |
T1624 |
Event Triggered Execution |
- |
| mobile |
T1624.001 |
Broadcast Receivers |
FakeSpy can register for the BOOT_COMPLETED broadcast Intent. |
| mobile |
T1628 |
Hide Artifacts |
- |
| mobile |
T1628.001 |
Suppress Application Icon |
FakeSpy can hide its icon if it detects that it is being run on an emulator. |
| mobile |
T1655 |
Masquerading |
- |
| mobile |
T1655.001 |
Match Legitimate Name or Location |
FakeSpy masquerades as local postal service applications. |
| mobile |
T1406 |
Obfuscated Files or Information |
FakeSpy stores its malicious code in encrypted asset files that are decrypted at runtime. Newer versions of FakeSpy encrypt the C2 address. |
| mobile |
T1636 |
Protected User Data |
- |
| mobile |
T1636.003 |
Contact List |
FakeSpy can collect the device’s contact list. |
| mobile |
T1636.004 |
SMS Messages |
FakeSpy can collect SMS messages. |
| mobile |
T1582 |
SMS Control |
FakeSpy can send SMS messages. |
| mobile |
T1418 |
Software Discovery |
FakeSpy can collect a list of installed applications. |
| mobile |
T1409 |
Stored Application Data |
FakeSpy can collect account information stored on the device, as well as data in external storage. |
| mobile |
T1426 |
System Information Discovery |
FakeSpy can collect device information, including OS version and device model. |
| mobile |
T1422 |
System Network Configuration Discovery |
FakeSpy can collect device networking information, including phone number, IMEI, and IMSI. |
| mobile |
T1422.001 |
Internet Connection Discovery |
FakeSpy can collect device networking information, including phone number, IMEI, and IMSI. |
| mobile |
T1421 |
System Network Connections Discovery |
FakeSpy can collect the device’s network information. |
| mobile |
T1633 |
Virtualization/Sandbox Evasion |
- |
| mobile |
T1633.001 |
System Checks |
FakeSpy can detect if it is running in an emulator and adjust its behavior accordingly. |