mobile |
T1626 |
Abuse Elevation Control Mechanism |
- |
mobile |
T1626.001 |
Device Administrator Permissions |
GPlayed can request device administrator permissions. |
mobile |
T1437 |
Application Layer Protocol |
- |
mobile |
T1437.001 |
Web Protocols |
GPlayed has communicated with the C2 using HTTP requests or WebSockets as a backup. |
mobile |
T1533 |
Data from Local System |
GPlayed can collect the user’s browser cookies. |
mobile |
T1407 |
Download New Code at Runtime |
GPlayed has the capability to remotely load plugins and download and compile new .NET code. |
mobile |
T1642 |
Endpoint Denial of Service |
GPlayed can lock the user out of the device by showing a persistent overlay. |
mobile |
T1624 |
Event Triggered Execution |
- |
mobile |
T1624.001 |
Broadcast Receivers |
GPlayed can register for the BOOT_COMPLETED broadcast intent. |
mobile |
T1630 |
Indicator Removal on Host |
- |
mobile |
T1630.002 |
File Deletion |
GPlayed can wipe the device. |
mobile |
T1417 |
Input Capture |
- |
mobile |
T1417.002 |
GUI Input Capture |
GPlayed can show a phishing WebView pretending to be a Google service that collects credit card information. |
mobile |
T1430 |
Location Tracking |
GPlayed can request the device’s location. |
mobile |
T1406 |
Obfuscated Files or Information |
GPlayed has base64-encoded the exfiltrated data, replacing some of the base64 characters to further obfuscate the data. |
mobile |
T1636 |
Protected User Data |
- |
mobile |
T1636.003 |
Contact List |
GPlayed can access the device’s contact list. |
mobile |
T1636.004 |
SMS Messages |
GPlayed can read SMS messages. |
mobile |
T1603 |
Scheduled Task/Job |
GPlayed has used timers to enable Wi-Fi, ping the C2 server, register the device with the C2, and register wake locks on the system. |
mobile |
T1582 |
SMS Control |
GPlayed can send SMS messages. |
mobile |
T1418 |
Software Discovery |
GPlayed can collect a list of installed applications. |
mobile |
T1426 |
System Information Discovery |
GPlayed can collect the device’s model, country, and Android version. |
mobile |
T1422 |
System Network Configuration Discovery |
GPlayed can collect the device’s IMEI, phone number, and country. |