LiveActive security incident?Get immediate response
MITRE ATT&CK® Malware

S0655: BusyGasper

MITRE ATT&CK S0655: BusyGasper Malware details for Android, with detection guidance, relationships and mapped CVEs.

MobileS0655MalwareObject v1.0Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceMedium

BusyGasper is an Android spyware entry in ATT&CK with a small reported victim set and infections described as requiring physical access to the device. Its significance is not broad-scale prevalence; it is the kind of mobile compromise that can matter greatly for executives, administrators, investigators, or other high-value users because the related behaviors include audio, video, screen, location, SMS, call, local data, and keystroke collection.

Executive priority

Treat this as a targeted mobile risk and custody-control problem rather than a commodity malware volume problem. Leaders should ask whether high-risk Android devices are inventoried, physically protected, permission-governed, and covered by mobile telemetry sufficient to support incident response and audit evidence. The business concern is exposure of sensitive communications, credentials, location, and meetings from a device that may otherwise look normal to the user.

Technical view

ATT&CK provides no official detection text for BusyGasper, so defenders should validate coverage against the related Android behaviors: runtime code download, access to stored application and local system data, keylogging, microphone/camera/screen capture, location tracking, SMS and call control, Unix shell use, icon suppression/user evasion, out-of-band communication, unencrypted exfiltration, and potential system binary modification. SOC and IR teams should focus on correlating unusual permission combinations, hidden or hard-to-remove applications, unexpected SMS/call/network activity, local data access, and signs of rooted or otherwise tampered devices.

Likely telemetry

  • Android device and application inventory, including package metadata and install history
  • Application permission grants for microphone, camera, location, SMS, phone, screen capture, accessibility, and keyboard-related capabilities
  • MDM/mobile security alerts for hidden applications, suppressed launcher icons, risky permissions, or policy violations
  • Network telemetry from mobile devices, especially unencrypted outbound protocols and unusual web-service communication patterns
  • SMS, call, and notification access indicators where legally and operationally available

Detection direction

  • Because MITRE provides no BusyGasper-specific detection, build behavior-based validation around the mapped techniques rather than relying on a malware name alone.
  • Prioritize correlation: a single permission such as location or microphone may be legitimate, but combinations of SMS control, call control, media capture, hidden icon behavior, runtime code download, and suspicious network activity should raise priority.
  • Tune against approved business applications, accessibility tools, mobile device management agents, communication apps, and support tools to reduce false positives.
  • Account for blind spots in BYOD, unmanaged Android devices, devices without mobile EDR/MDM, and telemetry that cannot observe SMS, calls, screen capture, or local storage access.
  • Include physical-access scenarios in triage: review custody history and recent hands-on support events when a high-risk Android device shows suspicious spyware-like behavior.

Mitigation priorities

  • Start with physical and administrative controls for high-risk Android devices: strong screen locks, controlled support handling, and documented chain-of-custody for executive or sensitive-user devices.
  • Use mobile device management or equivalent governance to maintain app inventory, enforce baseline configuration, and review high-risk permissions.
  • Limit installation of untrusted or unnecessary applications and validate apps that request sensitive permissions such as SMS, phone, microphone, camera, location, accessibility, or screen capture.
  • Prepare IR procedures for mobile spyware cases, including isolation, evidence preservation, review of sensitive accounts used on the device, and secure re-provisioning when compromise is suspected.
  • For compliance evidence, retain records showing managed-device coverage, permission review, device inventory, and response actions for high-risk mobile users.
Additional notes and limits

The most important decision value is the combination of physical-access infection reporting and broad surveillance behaviors. This makes BusyGasper most relevant to targeted mobile security, executive protection, insider/physical custody concerns, and IR readiness for Android devices rather than general malware prevalence tracking.

The supplied ATT&CK object does not include official detection guidance, aliases, labels, or tactics. Victim information is limited to the official description and one external SecureList reference. Local device telemetry, MDM coverage, legal constraints, and business-approved app baselines are required before assessing exposure or detection coverage.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

BusyGasper

No official description is available in the imported ATT&CK source object.

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

Relationship explorer

All related ATT&CK context

No relationships are available in the current normalized data for this object.

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
1.0
Created
Modified
Raw hash
83106e6111112b29...
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.