S0485: Mandrake
MITRE ATT&CK S0485: Mandrake Malware details for Android, with detection guidance, relationships and mapped CVEs.
Security context for executives and security teams
Mandrake is an Android espionage malware family described by ATT&CK as sophisticated, actively maintained, and able to remain dormant until operators issue commands. Its business significance is mobile trust: apparently legitimate apps can become an access path to sensitive communications, credentials, location, contacts, SMS, notifications, screenshots, and application data. For leaders, the key question is whether enterprise mobile controls can see beyond app reputation and installation status into permissions, runtime behavior, network patterns, and high-risk Android capabilities.
Executive priority
Prioritize Mandrake as a mobile espionage and data-exposure planning case, especially for executives, privileged users, regulated functions, and staff using Android devices for business communication or identity verification. The supplied ATT&CK relationships point to behaviors that can affect identity assurance, privacy obligations, incident scoping, and continuity of trusted communications: notification access, SMS control and collection, GUI/input capture, location tracking, foreground persistence, tool transfer, and command-and-control over web services, non-standard ports, or generated domains. Executives should ask whether mobile device management, app governance, and SOC workflows provide auditable evidence for installed apps, permissions, risky accessibility/device-admin use, and mobile network activity.
Technical view
ATT&CK provides no official detection text for Mandrake, so defenders should validate coverage through the related Android techniques. Focus on whether mobile telemetry can identify suspicious permission combinations and behavior such as downloaded code at runtime, obfuscated payloads, system and software discovery, access to stored app data, contacts, SMS, notifications, screen capture, location, accessibility-driven input injection, foreground service abuse, suppressed app icons, prevention of app removal, attempts to disable tools, file deletion, code-signing policy changes, sandbox/system checks, and C2-like communication using web services, non-standard ports, or DGA-style domains. Because the description says activation may depend on operator commands, static app review alone is an expected blind spot; behavioral monitoring and incident-ready device collection procedures are important.
Likely telemetry
- Android device inventory and OS/version/patch posture from MDM or EMM
- Installed application inventory, package metadata, signing status, app source, and application icon visibility where available
- App permission grants and changes, especially SMS, contacts, location, notification access, accessibility services, device administrator, foreground service, and screen capture-related capabilities
- Runtime behavior indicating dynamic code download, new file/tool transfer, obfuscated or encrypted payloads, or unusual file deletion
- Network telemetry for mobile devices, including DNS queries, generated-looking domains, web-service communication, unusual protocol/port pairings, and outbound connections from mobile apps
Detection direction
- Do not rely solely on app-store presence, reviews, or static pre-install scanning; the supplied description and T1407 relationship support concern for code downloaded after installation and command-triggered activation.
- Tune mobile detections around clusters of behavior rather than one permission: for example, accessibility or device-admin use combined with SMS/notification access, foreground persistence, screen capture, or prevention of removal is higher risk than an isolated permission grant.
- Validate DNS and web traffic analytics for mobile endpoints, including web-service C2 patterns, non-standard port use, and domain-generation-like behavior, while accounting for legitimate mobile app background traffic.
- Review whether MDM/EMM tools expose enough evidence to investigate suppressed app icons, device-admin abuse, app removal prevention, security-tool tampering, and runtime code download; many mobile programs lack this depth.
- Use allowlisting and exception review carefully: legitimate business apps may request contacts, location, notifications, or foreground services, so detections should include app reputation, business justification, user role, and behavior over time.
Mitigation priorities
- Start with mobile asset governance: identify Android devices used for sensitive business roles and ensure they are enrolled in managed controls where policy permits.
- Restrict or review high-risk Android permissions and capabilities, especially accessibility services, device administrator, SMS, notification access, contacts, location, screen capture, and installation from untrusted sources.
- Strengthen application governance with approved app lists, signing/source checks, and review of applications that download code at runtime or request permissions unrelated to business purpose.
- Ensure mobile network protections can inspect or log relevant DNS and outbound connection metadata for managed devices, including non-standard ports and suspicious domain patterns.
- Prepare incident response procedures for mobile devices, including how to preserve app inventory, permissions, network context, and user reports of uninstall problems or unusual prompts.
Additional notes and limits
The ATT&CK object identifies Mandrake as Android malware and links it to a broad set of mobile techniques spanning evasion, discovery, collection, command and control, persistence, defense evasion, and impact-like file deletion behavior. The strongest defensive value is using Mandrake as a test case for whether the organization can detect suspicious mobile behavior after installation, not merely block known bad apps.
This take is based only on the supplied ATT&CK object, external references, and relationship context. ATT&CK provides no official detection text, no tactics in the supplied fields, no aliases beyond the listed external-reference names, and no environment-specific indicators. The content should not be read as proof of current exploitation, attribution, customer exposure, or guaranteed detection coverage.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Mandrake
No official description is available in the imported ATT&CK source object.
How security teams should use this page
Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.
Techniques used
This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.
| Domain | ID | Name | Relationship / procedure |
|---|---|---|---|
| Mobile | T1655.001 | Match Legitimate Name or LocationSub-technique | This object uses Match Legitimate Name or Location. |
| Mobile | T1636.003 | Contact ListSub-technique | This object uses Contact List. |
| Mobile | T1633.001 | System ChecksSub-technique | This object uses System Checks. |
| Mobile | T1517 | Access Notifications | This object uses Access Notifications. |
| Mobile | T1541 | Foreground Persistence | This object uses Foreground Persistence. |
| Mobile | T1409 | Stored Application Data | This object uses Stored Application Data. |
| Mobile | T1509 | Non-Standard Port | This object uses Non-Standard Port. |
| Mobile | T1582 | SMS Control | This object uses SMS Control. |
| Mobile | T1513 | Screen Capture | This object uses Screen Capture. |
| Mobile | T1629.003 | Disable or Modify ToolsSub-technique | This object uses Disable or Modify Tools. |
| Mobile | T1406 | Obfuscated Files or Information | This object uses Obfuscated Files or Information. |
| Mobile | T1629.001 | Prevent Application RemovalSub-technique | This object uses Prevent Application Removal. |
| Mobile | T1481.002 | Bidirectional CommunicationSub-technique | This object uses Bidirectional Communication. |
| Mobile | T1516 | Input Injection | This object uses Input Injection. |
| Mobile | T1430 | Location Tracking | This object uses Location Tracking. |
| Mobile | T1418 | Software Discovery | This object uses Software Discovery. |
| Mobile | T1417.002 | GUI Input CaptureSub-technique | This object uses GUI Input Capture. |
| Mobile | T1632.001 | Code Signing Policy ModificationSub-technique | This object uses Code Signing Policy Modification. |
| Mobile | T1628.001 | Suppress Application IconSub-technique | This object uses Suppress Application Icon. |
| Mobile | T1407 | Download New Code at Runtime | This object uses Download New Code at Runtime. |
| Mobile | T1637.001 | Domain Generation AlgorithmsSub-technique | This object uses Domain Generation Algorithms. |
| Mobile | T1630.002 | File DeletionSub-technique | This object uses File Deletion. |
| Mobile | T1426 | System Information Discovery | This object uses System Information Discovery. |
| Mobile | T1544 | Ingress Tool Transfer | This object uses Ingress Tool Transfer. |
| Mobile | T1636.004 | SMS MessagesSub-technique | This object uses SMS Messages. |
All related ATT&CK context
Object version and sync metadata
The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.
Imported snapshots across ATT&CK releases(1)
| Release | Bundle imported | Object version | Modified | Status | Raw hash |
|---|---|---|---|---|---|
| 19.1 | 1.0 | Current bundle | 3d04d93f433b… |
Mirrored ATT&CK source object
The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.
External references and citations
MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.
- [1]Bitdefender Mandrake
R. Gevers, M. Tivadar, R. Bleotu, A. M. Barbatei, et al.. (2020, May 14). Uprooting Mandrake: The Story of an Advanced Android Spyware Framework That Went Undetected for 4 Years. Retrieved July 15, 2020.
Open source URL - [2]Bitdefender Mandrake
R. Gevers, M. Tivadar, R. Bleotu, A. M. Barbatei, et al.. (2020, May 14). Uprooting Mandrake: The Story of an Advanced Android Spyware Framework That Went Undetected for 4 Years. Retrieved July 15, 2020.
Open source URL - [3]briar
(Citation: Bitdefender Mandrake)
- [4]briar
(Citation: Bitdefender Mandrake)
- [5]darkmatter
(Citation: Bitdefender Mandrake)
- [6]darkmatter
(Citation: Bitdefender Mandrake)
- [7]mitre-attackS0485Open source URL
- [8]mitre-attackS0485Open source URL
- [9]oxide
(Citation: Bitdefender Mandrake)
- [10]oxide
(Citation: Bitdefender Mandrake)
- [11]ricinus
(Citation: Bitdefender Mandrake)
- [12]ricinus
(Citation: Bitdefender Mandrake)
- [13]Bitdefender Mandrake
R. Gevers, M. Tivadar, R. Bleotu, A. M. Barbatei, et al.. (2020, May 14). Uprooting Mandrake: The Story of an Advanced Android Spyware Framework That Went Undetected for 4 Years. Retrieved July 15, 2020.
Open source URL - [14]Bitdefender Mandrake
R. Gevers, M. Tivadar, R. Bleotu, A. M. Barbatei, et al.. (2020, May 14). Uprooting Mandrake: The Story of an Advanced Android Spyware Framework That Went Undetected for 4 Years. Retrieved July 15, 2020.
Open source URL - [15]Bitdefender Mandrake
R. Gevers, M. Tivadar, R. Bleotu, A. M. Barbatei, et al.. (2020, May 14). Uprooting Mandrake: The Story of an Advanced Android Spyware Framework That Went Undetected for 4 Years. Retrieved July 15, 2020.
Open source URL - [16]Bitdefender Mandrake
R. Gevers, M. Tivadar, R. Bleotu, A. M. Barbatei, et al.. (2020, May 14). Uprooting Mandrake: The Story of an Advanced Android Spyware Framework That Went Undetected for 4 Years. Retrieved July 15, 2020.
Open source URL - [17]Bitdefender Mandrake
R. Gevers, M. Tivadar, R. Bleotu, A. M. Barbatei, et al.. (2020, May 14). Uprooting Mandrake: The Story of an Advanced Android Spyware Framework That Went Undetected for 4 Years. Retrieved July 15, 2020.
Open source URL - [18]Bitdefender Mandrake
R. Gevers, M. Tivadar, R. Bleotu, A. M. Barbatei, et al.. (2020, May 14). Uprooting Mandrake: The Story of an Advanced Android Spyware Framework That Went Undetected for 4 Years. Retrieved July 15, 2020.
Open source URL - [19]Bitdefender Mandrake
R. Gevers, M. Tivadar, R. Bleotu, A. M. Barbatei, et al.. (2020, May 14). Uprooting Mandrake: The Story of an Advanced Android Spyware Framework That Went Undetected for 4 Years. Retrieved July 15, 2020.
Open source URL - [20]Bitdefender Mandrake
R. Gevers, M. Tivadar, R. Bleotu, A. M. Barbatei, et al.. (2020, May 14). Uprooting Mandrake: The Story of an Advanced Android Spyware Framework That Went Undetected for 4 Years. Retrieved July 15, 2020.
Open source URL - [21]Bitdefender Mandrake
R. Gevers, M. Tivadar, R. Bleotu, A. M. Barbatei, et al.. (2020, May 14). Uprooting Mandrake: The Story of an Advanced Android Spyware Framework That Went Undetected for 4 Years. Retrieved July 15, 2020.
Open source URL - [22]Bitdefender Mandrake
R. Gevers, M. Tivadar, R. Bleotu, A. M. Barbatei, et al.. (2020, May 14). Uprooting Mandrake: The Story of an Advanced Android Spyware Framework That Went Undetected for 4 Years. Retrieved July 15, 2020.
Open source URL - [23]Bitdefender Mandrake
R. Gevers, M. Tivadar, R. Bleotu, A. M. Barbatei, et al.. (2020, May 14). Uprooting Mandrake: The Story of an Advanced Android Spyware Framework That Went Undetected for 4 Years. Retrieved July 15, 2020.
Open source URL - [24]Bitdefender Mandrake
R. Gevers, M. Tivadar, R. Bleotu, A. M. Barbatei, et al.. (2020, May 14). Uprooting Mandrake: The Story of an Advanced Android Spyware Framework That Went Undetected for 4 Years. Retrieved July 15, 2020.
Open source URL - [25]Bitdefender Mandrake
R. Gevers, M. Tivadar, R. Bleotu, A. M. Barbatei, et al.. (2020, May 14). Uprooting Mandrake: The Story of an Advanced Android Spyware Framework That Went Undetected for 4 Years. Retrieved July 15, 2020.
Open source URL - [26]Bitdefender Mandrake
R. Gevers, M. Tivadar, R. Bleotu, A. M. Barbatei, et al.. (2020, May 14). Uprooting Mandrake: The Story of an Advanced Android Spyware Framework That Went Undetected for 4 Years. Retrieved July 15, 2020.
Open source URL - [27]Bitdefender Mandrake
R. Gevers, M. Tivadar, R. Bleotu, A. M. Barbatei, et al.. (2020, May 14). Uprooting Mandrake: The Story of an Advanced Android Spyware Framework That Went Undetected for 4 Years. Retrieved July 15, 2020.
Open source URL - [28]Bitdefender Mandrake
R. Gevers, M. Tivadar, R. Bleotu, A. M. Barbatei, et al.. (2020, May 14). Uprooting Mandrake: The Story of an Advanced Android Spyware Framework That Went Undetected for 4 Years. Retrieved July 15, 2020.
Open source URL - [29]Bitdefender Mandrake
R. Gevers, M. Tivadar, R. Bleotu, A. M. Barbatei, et al.. (2020, May 14). Uprooting Mandrake: The Story of an Advanced Android Spyware Framework That Went Undetected for 4 Years. Retrieved July 15, 2020.
Open source URL - [30]Bitdefender Mandrake
R. Gevers, M. Tivadar, R. Bleotu, A. M. Barbatei, et al.. (2020, May 14). Uprooting Mandrake: The Story of an Advanced Android Spyware Framework That Went Undetected for 4 Years. Retrieved July 15, 2020.
Open source URL - [31]Bitdefender Mandrake
R. Gevers, M. Tivadar, R. Bleotu, A. M. Barbatei, et al.. (2020, May 14). Uprooting Mandrake: The Story of an Advanced Android Spyware Framework That Went Undetected for 4 Years. Retrieved July 15, 2020.
Open source URL - [32]Bitdefender Mandrake
R. Gevers, M. Tivadar, R. Bleotu, A. M. Barbatei, et al.. (2020, May 14). Uprooting Mandrake: The Story of an Advanced Android Spyware Framework That Went Undetected for 4 Years. Retrieved July 15, 2020.
Open source URL - [33]Bitdefender Mandrake
R. Gevers, M. Tivadar, R. Bleotu, A. M. Barbatei, et al.. (2020, May 14). Uprooting Mandrake: The Story of an Advanced Android Spyware Framework That Went Undetected for 4 Years. Retrieved July 15, 2020.
Open source URL - [34]Bitdefender Mandrake
R. Gevers, M. Tivadar, R. Bleotu, A. M. Barbatei, et al.. (2020, May 14). Uprooting Mandrake: The Story of an Advanced Android Spyware Framework That Went Undetected for 4 Years. Retrieved July 15, 2020.
Open source URL - [35]Bitdefender Mandrake
R. Gevers, M. Tivadar, R. Bleotu, A. M. Barbatei, et al.. (2020, May 14). Uprooting Mandrake: The Story of an Advanced Android Spyware Framework That Went Undetected for 4 Years. Retrieved July 15, 2020.
Open source URL - [36]Bitdefender Mandrake
R. Gevers, M. Tivadar, R. Bleotu, A. M. Barbatei, et al.. (2020, May 14). Uprooting Mandrake: The Story of an Advanced Android Spyware Framework That Went Undetected for 4 Years. Retrieved July 15, 2020.
Open source URL - [37]Bitdefender Mandrake
R. Gevers, M. Tivadar, R. Bleotu, A. M. Barbatei, et al.. (2020, May 14). Uprooting Mandrake: The Story of an Advanced Android Spyware Framework That Went Undetected for 4 Years. Retrieved July 15, 2020.
Open source URL
Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.
