LiveActive security incident?Get immediate response
MITRE ATT&CK® Malware

S0320: DroidJack

MITRE ATT&CK S0320: DroidJack Malware details for Android, with detection guidance, relationships and mapped CVEs.

MobileS0320MalwareObject v1.2Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceHigh

DroidJack matters because it represents Android remote access malware that has been observed masquerading as popular legitimate apps. For security leaders, the practical issue is not the brand name alone; it is whether the organization can identify risky sideloaded or impersonated Android applications before they gain access to sensitive mobile sensors and data such as microphone audio, camera/video, call logs, and SMS messages.

Executive priority

Treat DroidJack as a mobile security readiness checkpoint. Executives should ask whether corporate Android devices, BYOD access paths, and mobile-enabled business processes have controls and evidence for application provenance, risky permissions, and potential data collection from microphones, cameras, call logs, and SMS. This is relevant to business continuity, privacy/compliance evidence, executive and workforce protection, and incident response decisions when mobile devices may handle sensitive communications.

Technical view

ATT&CK lists DroidJack for Android and relates it to Audio Capture, Video Capture, Call Log collection, SMS Messages collection, and matching a legitimate name or location. SOC, mobile security, and IR teams should validate whether they can see Android application inventory, package identity, install source, requested permissions, permission grant state, and suspicious use of sensitive APIs or content providers. Because no official ATT&CK detection text is provided, detection engineering should be based on the related behaviors and local mobile telemetry rather than a single malware-name alert.

Likely telemetry

  • Android application inventory and package metadata
  • Application install source and sideloading indicators
  • Requested and granted permissions, especially RECORD_AUDIO, camera access, call log access, and SMS access
  • Mobile device management or enterprise mobility management compliance records
  • Mobile threat defense alerts, if deployed

Detection direction

  • Validate coverage for Android devices specifically; do not assume desktop EDR coverage applies to this object.
  • Look for applications using legitimate-looking names, icons, or package conventions while requesting sensitive permissions inconsistent with business need.
  • Prioritize alerts where sideloaded or non-approved apps request microphone, camera, call log, or SMS access.
  • Tune false positives carefully because legitimate communication, conferencing, messaging, and support applications may request some of the same permissions.
  • Correlate package reputation, signing information, install source, permission grants, and user/device context before escalating.

Mitigation priorities

  • Establish or validate Android application allowlisting and approved app-store policies for managed devices.
  • Restrict or monitor sideloading where business requirements allow.
  • Use MDM/EMM policy to review and limit sensitive permissions for microphone, camera, call log, and SMS access.
  • Maintain mobile application inventory and compliance evidence for audit and incident response.
  • Educate users about lookalike applications posing as popular or trusted apps, especially outside approved distribution channels.
Additional notes and limits

The supplied ATT&CK object identifies DroidJack as Android malware observed posing as legitimate applications, with relationships to mobile collection and masquerading techniques. The strongest defensive value is to use this object as a test of mobile visibility and control maturity: can the team prove which Android apps are installed, where they came from, what permissions they have, and whether sensitive mobile data could be accessed?

ATT&CK does not provide tactics or official detection content for this object in the supplied fields. The source material supports Android only and does not support claims about current activity, attribution, prevalence, specific victims, or guaranteed detection. Local device management, mobile telemetry, and forensic evidence are required to assess exposure or compromise.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

DroidJack

No official description is available in the imported ATT&CK source object.

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

Relationship explorer

All related ATT&CK context

No relationships are available in the current normalized data for this object.

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
1.2
Created
Modified
Raw hash
daa5a704a151c140...
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.