AppLite: A New AntiDot Variant Targeting Mobile Employee Devices
Tags
cmtmf-attack-pattern: Event Triggered Execution Masquerading Obfuscated Files Or Information Uninstall Malicious Application
country: Australia Canada Germany France Italy Spain Portugal Russia
maec-delivery-vectors: Watering Hole
attack-pattern: Data Direct Access Notifications - T1517 Broadcast Receivers - T1402 Software Discovery - T1418 Audio Capture - T1429 Bidirectional Communication - T1102.002 Bidirectional Communication - T1481.002 Broadcast Receivers - T1624.001 Call Control - T1616 Call Log - T1636.002 Clipboard Data - T1414 Contact List - T1636.003 Credentials - T1589.001 Domains - T1583.001 Domains - T1584.001 Dynamic Resolution - T1637 Dynamic Resolution - T1568 Event Triggered Execution - T1624 Event Triggered Execution - T1546 Exfiltration Over C2 Channel - T1646 Gui Input Capture - T1056.002 Gui Input Capture - T1417.002 Indicator Removal On Host - T1630 Input Capture - T1417 Input Injection - T1516 Javascript - T1059.007 Keylogging - T1056.001 Keylogging - T1417.001 Malware - T1587.001 Malware - T1588.001 Masquerading - T1655 Match Legitimate Name Or Location - T1036.005 Match Legitimate Name Or Location - T1655.001 Obfuscated Files Or Information - T1406 System Information Discovery - T1426 Phishing - T1660 Phishing - T1566 Protected User Data - T1636 Screen Capture - T1513 Server - T1583.004 Server - T1584.004 Sms Control - T1582 Sms Messages - T1636.004 Social Media - T1593.001 Software Discovery - T1518 Software Packing - T1027.002 Software Packing - T1406.002 Vnc - T1021.005 Web Service - T1481 Video Capture - T1512 Uninstall Malicious Application - T1576 Uninstall Malicious Application - T1630.001 Audio Capture - T1123 Clipboard Data - T1115 Exfiltration Over Command And Control Channel - T1041 Indicator Removal On Host - T1070 Input Capture - T1056 Masquerading - T1036 Obfuscated Files Or Information - T1027 Screen Capture - T1113 Software Packing - T1045 System Information Discovery - T1082 Web Service - T1102 Indicator Removal On Host Masquerading Screen Capture
Common Information
Type Value
UUID 80e2b2a6-c752-447b-b543-3c8289f055fb
Fingerprint dc311c198973afc5
Analysis status DONE
Considered CTI value 2
Text language
Published Dec. 10, 2024, 9 a.m.
Added to db Dec. 10, 2024, 4:24 p.m.
Last updated Dec. 18, 2024, 11:01 p.m.
Headline AppLite: A New AntiDot Variant Targeting Mobile Employee Devices
Title AppLite: A New AntiDot Variant Targeting Mobile Employee Devices
Detected Hints/Tags/Attributes 155/4/148
RSS Feed
Details Id Enabled Feed title Url Added to db
Details 226 Security Boulevard https://securityboulevard.com/feed 2024-08-30 22:08
Attributes
Details Type #Events CTI Value
Details Domain 54
socket.io
Details Domain 197
com.android
Details Domain 19
au.com.ingdirect.android
Details Domain 22
org.westpac.bank
Details Domain 7
ca.tangerine.clients.banking.app
Details Domain 7
com.changelly.app
Details Domain 19
com.cibc.android.mobi
Details Domain 18
com.paypal.android
Details Domain 8
com.pcfinancial.mobile
Details Domain 15
com.rbc.mobile.android
Details Domain 15
com.td
Details Domain 6
co.bitx.android
Details Domain 6
co.edgesecure.app
Details Domain 8
co.mona.android
Details Domain 76
crypto.com
Details Domain 27
com.commbank.netbank
Details Domain 28
com.binance.dev
Details Domain 6
com.btcturk.pro
Details Domain 5
com.bybit.app
Details Domain 13
com.bmo.mobile
Details Domain 6
com.enjin.mobile
Details Domain 5
exmo.com
Details Domain 6
com.gemini.android.app
Details Domain 23
org.stgeorge.bank
Details Domain 15
st.george
Details Domain 8
com.kraken.trade
Details Domain 5
com.lumiwallet.android
Details Domain 9
com.okinc.okex.gp
Details Domain 7
com.paribu.app
Details Domain 5
com.robinhood.android
Details Domain 6
com.tabtrader.android
Details Domain 8
id.co
Details Domain 5
io.cex.app.prod
Details Domain 42
cex.io
Details Domain 25
com.coinbase.android
Details Domain 7
jp.coincheck.android
Details Domain 8
lt.spectrofinance.spectrocoin.android
Details Domain 6
me.cryptopay.android
Details Domain 9
net.bitstamp.app
Details Domain 21
piuk.blockchain.android
Details Domain 48
blockchain.com
Details Domain 11
app.wizink.es
Details Domain 29
com.bbva
Details Domain 16
com.cajasur.android
Details Domain 15
com.imaginbank.app
Details Domain 27
es.lacaixa.mobile.android
Details Domain 15
es.openbank.mobile
Details Domain 8
ca.mobile
Details Domain 9
cgd.pt
Details Domain 8
com.abanca.bm.pt
Details Domain 8
com.bbva.mobile.pt
Details Domain 10
pt.bancobpi.mobile
Details Domain 7
pt.sibs.android
Details Domain 19
wit.android
Details Domain 7
com.electroneum.mobile
Details Domain 21
com.anz.android
Details Domain 24
au.com.nab.mobile
Details Domain 30
au.com
Details Domain 20
com.bendigobank.mobile
Details Domain 10
com.schwab.mobile
Details Domain 3
com.marcus.android
Details Domain 3
com.varomoney.bank
Details Domain 9
com.mtb.mbanking.sc.retail.prod
Details Domain 9
com.americanexpress.android.acctsvcs.us
Details Domain 17
com.discoverfinancial.mobile
Details Domain 7
com.desjardins.mobile
Details Domain 11
com.pnc.ecommerce.mobile
Details Domain 17
com.citi
Details Domain 19
com.usaa.mobile.android
Details Domain 22
com.wf
Details Domain 9
com.navyfederal.android
Details Domain 7
com.squareup.cash
Details Domain 5
com.truist.mobile
Details Domain 22
com.konylabs.capitalone
Details Domain 23
com.infonow.bofa
Details Domain 6
com.bmoharris.digital
Details Domain 7
ca.pcfinancial.bank
Details Domain 10
com.ally
Details Domain 8
ca.bnc.android
Details Domain 10
com.key.android
Details Domain 22
com.chase.sig.android
Details Domain 8
com.transferwise.android
Details Domain 7
ca.affinitycu.mobile
Details Domain 7
com.meridian.android
Details Domain 62
com.google.android
Details Domain 19
com.google.android.gm
Details Domain 5
com.payoneer.android
Details Domain 2
com.bittrex.trade
Details Domain 4
com.huobionchainwallet.gp
Details Domain 6
com.polehin.android
Details Domain 5
doge.org.freewallet.app
Details Domain 4
global.bithumb.android
Details Domain 9
hr.asseco.android
Details Domain 10
com.indra.itecban.mobile
Details Domain 10
com.indra.itecban.triodosbank.mobile
Details Domain 24
es.cm.android
Details Domain 2
com.fifththird.mobile
Details Domain 19
www.zimperium.com
Details File 32
android.sys
Details File 19
com.rb
Details File 9
android.wallet
Details File 58
com.pl
Details File 37
com.bin
Details File 11
bitpay.wallet
Details File 6
mobile.wallet
Details File 15
st.geo
Details File 13
mycelium.wallet
Details File 6
paxful.wallet
Details File 8
com.tab
Details File 3
tronlinkpro.wallet
Details File 13
com.wallet
Details File 3
io.safe
Details File 3
pal.wallet
Details File 34
com.db
Details File 20
bcpbankingapp.mil
Details File 7
com.reg
Details File 30
com.inf
Details File 24
com.key
Details File 6
apps.wallet
Details File 23
com.ai
Details File 7
samourai.wallet
Details File 9
com.wav
Details File 7
esplatform.wallet
Details File 29
com.tar
Details MITRE ATT&CK Techniques 19
T1660
Details MITRE ATT&CK Techniques 16
T1624.001
Details MITRE ATT&CK Techniques 8
T1655.001
Details MITRE ATT&CK Techniques 6
T1630.001
Details MITRE ATT&CK Techniques 17
T1516
Details MITRE ATT&CK Techniques 17
T1406.002
Details MITRE ATT&CK Techniques 6
T1414
Details MITRE ATT&CK Techniques 15
T1417.001
Details MITRE ATT&CK Techniques 11
T1417.002
Details MITRE ATT&CK Techniques 14
T1517
Details MITRE ATT&CK Techniques 26
T1418
Details MITRE ATT&CK Techniques 29
T1426
Details MITRE ATT&CK Techniques 19
T1513
Details MITRE ATT&CK Techniques 14
T1512
Details MITRE ATT&CK Techniques 26
T1429
Details MITRE ATT&CK Techniques 12
T1616
Details MITRE ATT&CK Techniques 17
T1636.002
Details MITRE ATT&CK Techniques 22
T1636.003
Details MITRE ATT&CK Techniques 22
T1636.004
Details MITRE ATT&CK Techniques 5
T1637
Details MITRE ATT&CK Techniques 4
T1481.002
Details MITRE ATT&CK Techniques 20
T1646
Details MITRE ATT&CK Techniques 17
T1582
Details Url 2
https://www.zimperium.com/blog/applite-a-new-antidot-variant-targeting-mobile-employee-devices