test_scratch
/
cti-ATT-CK-v13.1
/mobile-attack
/malware
/malware--4b53eb01-57d7-47b4-b078-22766b002b36.json
{ | |
"type": "bundle", | |
"id": "bundle--89dd569f-7b05-447e-8151-2e7911a11aa8", | |
"spec_version": "2.0", | |
"objects": [ | |
{ | |
"modified": "2023-04-13T22:32:16.509Z", | |
"name": "S.O.V.A.", | |
"description": "[S.O.V.A.](https://attack.mitre.org/software/S1062) is an Android banking trojan that was first identified in August 2021 and has subsequently been found in a variety of applications, including banking, cryptocurrency wallet/exchange, and shopping apps. [S.O.V.A.](https://attack.mitre.org/software/S1062), which is Russian for \"owl\", contains features not commonly found in Android malware, such as session cookie theft.(Citation: threatfabric_sova_0921)(Citation: cleafy_sova_1122)", | |
"x_mitre_platforms": [ | |
"Android" | |
], | |
"x_mitre_deprecated": false, | |
"x_mitre_domains": [ | |
"mobile-attack" | |
], | |
"x_mitre_version": "1.0", | |
"x_mitre_aliases": [ | |
"S.O.V.A." | |
], | |
"type": "malware", | |
"id": "malware--4b53eb01-57d7-47b4-b078-22766b002b36", | |
"created": "2023-02-06T19:34:43.026Z", | |
"created_by_ref": "identity--c78cb6e5-0c4b-4611-8297-d1b8b55e40b5", | |
"revoked": false, | |
"external_references": [ | |
{ | |
"source_name": "mitre-attack", | |
"url": "https://attack.mitre.org/software/S1062", | |
"external_id": "S1062" | |
}, | |
{ | |
"source_name": "cleafy_sova_1122", | |
"description": "Francesco Lubatti, Federico Valentini. (2022, November 8). SOVA malware is back and is evolving rapidly. Retrieved March 30, 2023.", | |
"url": "https://www.cleafy.com/cleafy-labs/sova-malware-is-back-and-is-evolving-rapidly" | |
}, | |
{ | |
"source_name": "threatfabric_sova_0921", | |
"description": "ThreatFabric. (2021, September 9). S.O.V.A. - A new Android Banking trojan with fowl intentions. Retrieved February 6, 2023.", | |
"url": "https://www.threatfabric.com/blogs/sova-new-trojan-with-fowl-intentions.html" | |
} | |
], | |
"object_marking_refs": [ | |
"marking-definition--fa42a846-8d90-4e51-bc29-71d5b4802168" | |
], | |
"labels": [ | |
"malware" | |
], | |
"x_mitre_attack_spec_version": "3.1.0", | |
"x_mitre_modified_by_ref": "identity--c78cb6e5-0c4b-4611-8297-d1b8b55e40b5" | |
} | |
] | |
} |