{ "type": "bundle", "id": "bundle--d0eef57c-ff9e-4405-b19c-db501fe70522", "spec_version": "2.0", "objects": [ { "labels": [ "malware" ], "x_mitre_platforms": [ "Android" ], "x_mitre_domains": [ "mobile-attack" ], "x_mitre_contributors": [ "Ofir Almkias, Cybereason" ], "x_mitre_aliases": [ "FakeSpy" ], "object_marking_refs": [ "marking-definition--fa42a846-8d90-4e51-bc29-71d5b4802168" ], "id": "malware--838f647e-8ff8-48bd-bbd5-613cee7736cb", "type": "malware", "created": "2020-09-15T15:18:11.971Z", "created_by_ref": "identity--c78cb6e5-0c4b-4611-8297-d1b8b55e40b5", "external_references": [ { "external_id": "S0509", "source_name": "mitre-attack", "url": "https://attack.mitre.org/software/S0509" }, { "source_name": "Cybereason FakeSpy", "url": "https://www.cybereason.com/blog/fakespy-masquerades-as-postal-service-apps-around-the-world", "description": "O. Almkias. (2020, July 1). FakeSpy Masquerades as Postal Service Apps Around the World. Retrieved September 15, 2020." } ], "modified": "2020-10-06T20:09:57.659Z", "name": "FakeSpy", "description": "[FakeSpy](https://attack.mitre.org/software/S0509) is Android spyware that has been operated by the Chinese threat actor behind the Roaming Mantis campaigns.(Citation: Cybereason FakeSpy)", "x_mitre_version": "1.0", "x_mitre_attack_spec_version": "2.1.0", "x_mitre_modified_by_ref": "identity--c78cb6e5-0c4b-4611-8297-d1b8b55e40b5" } ] }