LiveActive security incident?Get immediate response
MITRE ATT&CK® Malware

S0425: Corona Updates

Corona Updates is Android spyware that took advantage of the Coronavirus pandemic. The campaign distributing this spyware is tracked as Project Spy. Multiple variants of this spyware have been discovered to have been hosted on the Google Play Store.[1]

MobileS0425MalwareObject v1.1Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceMedium

Corona Updates is an Android spyware entry tied by MITRE to a pandemic-themed campaign and multiple variants reportedly hosted on Google Play. Its importance is less the theme and more the mobile data-access pattern: the related behaviors include collecting contacts, SMS, call logs, local data, location, audio/video, notifications, and network/system details, with web-protocol communications and possible unencrypted exfiltration. For leaders, this is a reminder that approved-app-store sourcing alone is not sufficient mobile risk control.

Executive priority

Prioritize this as a mobile privacy, identity, and incident-readiness issue for Android fleets, especially where phones handle MFA codes, executive communications, regulated data, or sensitive field operations. Ask whether mobile device governance can prove which apps are installed, which permissions are granted, whether notification/SMS access is controlled, and whether incident responders can collect enough endpoint and network evidence to scope exposure. The object has no ATT&CK-provided detection text, so assurance should come from validated telemetry and policy enforcement, not assumptions.

Technical view

SOC and IR teams should validate Android-focused coverage for spyware behaviors mapped to this object: system and network discovery, Internet and Wi-Fi discovery, system information discovery, audio/video/location collection, notification access, local data access, SMS control, call log/contact/SMS collection, web-protocol communications, and unencrypted non-C2 exfiltration. Review app inventory, package metadata, requested/granted permissions, default SMS-handler status, notification listener access, microphone/camera/location use, content-provider access where available, and outbound HTTP/HTTPS or other cleartext destinations. Because ATT&CK provides no detection guidance or tactics for this malware object, detections should be behavior- and permission-oriented rather than name-only.

Likely telemetry

  • Android app inventory and package installation history
  • Application requested and granted permissions, including SMS, contacts, call log, location, microphone, camera, notification access, and storage-related permissions
  • Default SMS-handler and notification listener configuration state
  • Mobile device management or enterprise mobility management compliance events
  • Mobile threat defense or endpoint security alerts for spyware-like behavior

Detection direction

  • Do not rely only on the Corona Updates name; validate behaviors aligned to the related ATT&CK techniques and suspicious permission combinations.
  • Tune for apps that combine sensitive collection permissions with network communications, especially SMS/contact/call-log/location/microphone/camera/notification access.
  • Review mobile network logs for unusual web-protocol communication patterns and any cleartext exfiltration-like traffic, while accounting for normal mobile app background traffic.
  • Correlate app install time, permission grants, and outbound communications to reduce false positives from legitimate communications, health, messaging, or device-management apps.
  • Confirm visibility gaps for personally owned devices, devices not routed through enterprise network controls, and Android versions or privacy settings that limit collection.

Mitigation priorities

  • Maintain enforceable Android app governance: approved app sources, app inventory, risky-app review, and removal workflows.
  • Restrict or require justification for high-risk permissions such as SMS, notification access, call logs, contacts, location, microphone, camera, and storage.
  • Use mobile device management or equivalent controls to enforce baseline configuration and collect compliance evidence for audit and incident response.
  • Reduce identity risk by avoiding SMS-only authentication where possible and monitoring for mobile conditions that could expose one-time codes or notifications.
  • Route managed mobile traffic through monitored controls where feasible, and block or alert on cleartext exfiltration paths consistent with policy.
Additional notes and limits

The supplied ATT&CK object identifies Corona Updates as Android spyware associated with Project Spy and cites Trend Micro reporting from April 2020. MITRE relationships provide a broad behavior set spanning discovery, collection, command-and-control over web protocols, SMS control, and exfiltration. The practical defensive value is to test whether mobile security controls can see and govern these behaviors across Android devices rather than to match only one malware name.

ATT&CK provides no official detection text, no aliases, no labels, and no tactics for this malware object in the supplied fields. The relationship descriptions are technique-level context and do not prove every behavior occurred in every variant or in a specific environment. Local app inventory, permission state, mobile telemetry, and network evidence are required before assessing exposure or confirming activity.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

Corona Updates

Corona Updates is Android spyware that took advantage of the Coronavirus pandemic. The campaign distributing this spyware is tracked as Project Spy. Multiple variants of this spyware have been discovered to have been hosted on the Google Play Store.[1]

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

ATT&CK relationship table

Techniques used

This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.

15 rows
DomainIDNameRelationship / procedure
MobileT1582SMS Control

Corona Updates can send SMS messages.[1]

MobileT1636.002Call LogSub-technique

Corona Updates can collect the device’s call log.[1]

MobileT1517Access Notifications

Corona Updates can collect messages from GSM, WhatsApp, Telegram, Facebook, and Threema by reading the application’s notification content.[1]

MobileT1430Location Tracking

Corona Updates can track the device’s location.[1]

MobileT1533Data from Local System

Corona Updates can collect voice notes, device accounts, and gallery images.[1]

MobileT1512Video Capture

Corona Updates can take pictures using the camera and can record MP4 files.[1]

MobileT1636.003Contact ListSub-technique

Corona Updates can collect device contacts.[1]

MobileT1636.004SMS MessagesSub-technique

Corona Updates can collect SMS messages.[1]

MobileT1429Audio Capture

Corona Updates can record MP4 files and monitor calls.[1]

MobileT1437.001Web ProtocolsSub-technique

Corona Updates communicates with the C2 server using HTTP requests.[1]

MobileT1422System Network Configuration Discovery

Corona Updates can collect device network configuration information, such as Wi-Fi SSID and IMSI.[1]

MobileT1426System Information Discovery

Corona Updates can collect various pieces of device information, including OS version, phone model, and manufacturer.[1]

MobileT1639.001Exfiltration Over Unencrypted Non-C2 ProtocolSub-technique

Corona Updates has exfiltrated data using FTP.[1]

MobileT1422.001Internet Connection DiscoverySub-technique

Corona Updates can collect device network configuration information, such as Wi-Fi SSID and IMSI.[1]

MobileT1422.002Wi-Fi DiscoverySub-technique

Corona Updates can collect device network configuration information, such as Wi-Fi SSID and IMSI.[1]

Relationship explorer

All related ATT&CK context

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
1.1
Created
Modified
Raw hash
9fc6f89699f23275...
Imported snapshots across ATT&CK releases(1)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.11.1Current bundle9fc6f89699f2…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    TrendMicro Coronavirus Updates

    T. Bao, J. Lu. (2020, April 14). Coronavirus Update App Leads to Project Spy Android and iOS Spyware. Retrieved April 24, 2020.

    Open source URL
  2. [2]
    Concipit1248

    (Citation: TrendMicro Coronavirus Updates)

  3. [3]
    Concipit1248

    (Citation: TrendMicro Coronavirus Updates)

  4. [4]
    TrendMicro Coronavirus Updates

    T. Bao, J. Lu. (2020, April 14). Coronavirus Update App Leads to Project Spy Android and iOS Spyware. Retrieved April 24, 2020.

    Open source URL
  5. [5]
    Wabi Music

    (Citation: TrendMicro Coronavirus Updates)

  6. [6]
    Wabi Music

    (Citation: TrendMicro Coronavirus Updates)

  7. [7]
    mitre-attackS0425
    Open source URL
  8. [8]
    mitre-attackS0425
    Open source URL
  9. [9]
    TrendMicro Coronavirus Updates

    T. Bao, J. Lu. (2020, April 14). Coronavirus Update App Leads to Project Spy Android and iOS Spyware. Retrieved April 24, 2020.

    Open source URL
  10. [10]
    TrendMicro Coronavirus Updates

    T. Bao, J. Lu. (2020, April 14). Coronavirus Update App Leads to Project Spy Android and iOS Spyware. Retrieved April 24, 2020.

    Open source URL
  11. [11]
    TrendMicro Coronavirus Updates

    T. Bao, J. Lu. (2020, April 14). Coronavirus Update App Leads to Project Spy Android and iOS Spyware. Retrieved April 24, 2020.

    Open source URL
  12. [12]
    TrendMicro Coronavirus Updates

    T. Bao, J. Lu. (2020, April 14). Coronavirus Update App Leads to Project Spy Android and iOS Spyware. Retrieved April 24, 2020.

    Open source URL
  13. [13]
    TrendMicro Coronavirus Updates

    T. Bao, J. Lu. (2020, April 14). Coronavirus Update App Leads to Project Spy Android and iOS Spyware. Retrieved April 24, 2020.

    Open source URL
  14. [14]
    TrendMicro Coronavirus Updates

    T. Bao, J. Lu. (2020, April 14). Coronavirus Update App Leads to Project Spy Android and iOS Spyware. Retrieved April 24, 2020.

    Open source URL
  15. [15]
    TrendMicro Coronavirus Updates

    T. Bao, J. Lu. (2020, April 14). Coronavirus Update App Leads to Project Spy Android and iOS Spyware. Retrieved April 24, 2020.

    Open source URL
  16. [16]
    TrendMicro Coronavirus Updates

    T. Bao, J. Lu. (2020, April 14). Coronavirus Update App Leads to Project Spy Android and iOS Spyware. Retrieved April 24, 2020.

    Open source URL
  17. [17]
    TrendMicro Coronavirus Updates

    T. Bao, J. Lu. (2020, April 14). Coronavirus Update App Leads to Project Spy Android and iOS Spyware. Retrieved April 24, 2020.

    Open source URL
  18. [18]
    TrendMicro Coronavirus Updates

    T. Bao, J. Lu. (2020, April 14). Coronavirus Update App Leads to Project Spy Android and iOS Spyware. Retrieved April 24, 2020.

    Open source URL
  19. [19]
    TrendMicro Coronavirus Updates

    T. Bao, J. Lu. (2020, April 14). Coronavirus Update App Leads to Project Spy Android and iOS Spyware. Retrieved April 24, 2020.

    Open source URL
  20. [20]
    TrendMicro Coronavirus Updates

    T. Bao, J. Lu. (2020, April 14). Coronavirus Update App Leads to Project Spy Android and iOS Spyware. Retrieved April 24, 2020.

    Open source URL
  21. [21]
    TrendMicro Coronavirus Updates

    T. Bao, J. Lu. (2020, April 14). Coronavirus Update App Leads to Project Spy Android and iOS Spyware. Retrieved April 24, 2020.

    Open source URL
  22. [22]
    TrendMicro Coronavirus Updates

    T. Bao, J. Lu. (2020, April 14). Coronavirus Update App Leads to Project Spy Android and iOS Spyware. Retrieved April 24, 2020.

    Open source URL
  23. [23]
    TrendMicro Coronavirus Updates

    T. Bao, J. Lu. (2020, April 14). Coronavirus Update App Leads to Project Spy Android and iOS Spyware. Retrieved April 24, 2020.

    Open source URL
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.