LiveActive security incident?Get immediate response
MITRE ATT&CK® Malware

S9006: VajraSpy

VajraSpy is Android malware distributed via trojanized messaging and news applications. It has been used to target individuals in Pakistan and India since at least 2021 and has been delivered through the Google Play Store, malicious domains, and other uncontrolled distribution channels. VajraSpy is attributed with high confidence to Patchwork which has used the malware to conduct targeted espionage, primarily against devices in Pakistan.[1][2][3]

MobileS9006MalwareObject v1.0Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceMedium

S9006: VajraSpy describes [VajraSpy](https://attack.mitre.org/software/S9006) is Android malware distributed via trojanized messaging and news applications. It has been used to target individuals in Pakistan and India since at least 2021 and has been delivered through the Google Play Store, malicious domains, and other uncontrolled distribution channels. [VajraSpy](https://attack.mitre.org/software/S9006) is attributed with high confidence to [Patchwork](https://attack.mitre.org/groups/G0040) which has used the malware to conduct targeted e...

Executive priority

S9006: VajraSpy is an official MITRE ATT&CK software. Glexia treats it as defensive behavior context for prioritizing monitoring, control validation, and response planning without using the object by itself as an attribution claim.

Technical view

Security teams should validate S9006: VajraSpy by reviewing the official ATT&CK relationships, mapped tactics (the mapped ATT&CK tactic context), supported platforms (Android), and available local telemetry before making detection or mitigation decisions.

Likely telemetry

  • Official ATT&CK relationships and object metadata

Detection direction

  • Validate whether S9006: VajraSpy appears in your detection coverage and tabletop scenarios.
  • Use the object to align executive risk language with SOC, incident response, and detection engineering work.
  • Do not treat ATT&CK relationship context as attribution without corroborating evidence.

Mitigation priorities

  • Map the object to existing controls and identify missing telemetry or response ownership.
  • Prioritize mitigations that reduce exposure on the listed platforms and tactics.
  • Review adjacent ATT&CK relationships before changing policy, detections, or reporting language.
Additional notes and limits

Baseline Glexia take generated from the official MITRE ATT&CK STIX object, source hash, tactics, platforms, and detection fields. It is safe to replace with a richer model-generated take for the same source hash later.

This baseline take is source-grounded and schema-validated, but it does not include environment-specific telemetry, incident evidence, or threat-intelligence corroboration.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

VajraSpy

VajraSpy is Android malware distributed via trojanized messaging and news applications. It has been used to target individuals in Pakistan and India since at least 2021 and has been delivered through the Google Play Store, malicious domains, and other uncontrolled distribution channels. VajraSpy is attributed with high confidence to Patchwork which has used the malware to conduct targeted espionage, primarily against devices in Pakistan.[1][2][3]

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

ATT&CK relationship table

Techniques used

This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.

23 rows
DomainIDNameRelationship / procedure
MobileT1639.001Exfiltration Over Unencrypted Non-C2 ProtocolSub-technique

VajraSpy has used Retrofit, an HTTP client for Android, to upload unencrypted data to the C2 server via HTTP.[1]

MobileT1453Abuse Accessibility Features

VajraSpy has exploited accessibility features to intercept and exfiltrate communication from WhatsApp, WhatsApp Business and Signal and to automatically enable necessary permissions on the user’s behalf.[1]

MobileT1636.002Call LogSub-technique

VajraSpy has collected and exfiltrated the call log.[1][3]

MobileT1429Audio Capture

VajraSpy has recorded surrounding audio and phone calls from WhatsApp, WhatsApp Business, Signal, and Telegram by requesting `android.permission.RECORD_AUDIO`.[1][3]

MobileT1430Location Tracking

VajraSpy has exfiltrated the device’s location.[1] VajraSpy has also requested for `android.permission.ACCESS_FINE_LOCATION` and `android.permission.ACCESS_COARSE_LOCATION` to obtain the device’s location.[3]

MobileT1426System Information Discovery

VajraSpy has requested for `android.permission.READ_PHONE_STATE` to collect information about the device.[3]

MobileT1461Lockscreen Bypass

VajraSpy has requested for `android.permission.DISABLE_KEYGUARD` to disable the device lock screen password.[3]

MobileT1420File and Directory Discovery

VajraSpy has searched for files with specific extensions, such as .txt, .jpg, .Om4a, .aac and .opus, before exfiltration.[1]

MobileT1636.005AccountsSub-technique

VajraSpy has requested for `android.permission.GET_ACCOUNTS`.[3]

MobileT1636.004SMS MessagesSub-technique

VajraSpy has collected and exfiltrated SMS messages.[1][3]

MobileT1517Access Notifications

VajraSpy has monitored and exfiltrated notifications from messaging applications and from SMS messages.[1]

MobileT1422.002Wi-Fi DiscoverySub-technique

VajraSpy has scanned for Wi-Fi networks.[1]

MobileT1636.003Contact ListSub-technique

VajraSpy has collected and exfiltrated the contact list.[1][3]

MobileT1512Video Capture

VajraSpy has captured pictures using the device’s camera by requesting for `android.permission.CAMERA`.[1][3]

MobileT1409Stored Application Data

VajraSpy has collected messages in WhatsApp, WhatsApp Business, and Signal.[1][3]

MobileT1660Phishing

VajraSpy has used a romance trap scam to convince victims into downloading the trojanized application.[1]

MobileT1655Masquerading

VajraSpy has masqueraded as messaging and news applications.[1][3]

MobileT1481.002Bidirectional CommunicationSub-technique

VajraSpy has used Firebase and Google Cloud Storage to send and receive C2 communications and to send collected data.[1][3]

MobileT1616Call Control

VajraSpy has requested for `android.permission.CALL_PHONE`.[3]

MobileT1646Exfiltration Over C2 Channel

VajraSpy has exfiltrated captured data to C2 via POST requests.[1]

MobileT1417.001KeyloggingSub-technique

VajraSpy has logged keystrokes of an infected device.[1]

MobileT1418Software Discovery

VajraSpy has obtained and exfiltrated a list of installed applications.[1][3]

MobileT1533Data from Local System

VajraSpy has collected files with specific extensions, such as .txt, .jpg, .Om4a, .aac and .opus, before exfiltration.[1] VajraSpy has also requested for `android.permission.WRITE_EXTERNAL_STORAGE` and `android.permission.READ_EXTERNAL_STORAGE`.[3]

Associated objects

Groups, software, and campaigns

GroupMobile

G0040: Patchwork

Patchwork is a cyber espionage group that was first observed in December 2015. While the group has not been definitively attributed, circumstantial evidence suggests the group may be a pro-Indian or Indian entity. Patchwork has been seen targeting industries related to diplomatic and government agencies. Much of the code used by this group was copied and pasted from online forums. Patchwork was also seen operating spearphishing campaigns targeting U.S. think tank groups in March and April of 2018.[1] [2][3][4]

Relationship explorer

All related ATT&CK context

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.2
Object version
1.0
Created
Modified
Raw hash
4cfcd337d5c0211e...
Imported snapshots across ATT&CK releases(2)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.21.0Current bundle4cfcd337d5c0…
19.11.0Older bundle4cfcd337d5c0…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    ESET_VajraSpy_Feb2024

    Stefanko, L. (2024, February 1). VajraSpy: A Patchwork of espionage apps. Retrieved October 27, 2025.

    Open source URL
  2. [2]
    ArcticWolf_DroppingElephant_July2025

    ArcticWolf. (2025, July 23). Dropping Elephant APT Group Targets Turkish Defense Industry With New Campaign and Capabilities: LOLBAS, VLC Player, and Encrypted Shellcode. Retrieved November 3, 2025.

    Open source URL
  3. [3]
    K7Dhanalakshmi_VajraSpy_April2022

    Dhanalakshmi. (2022, April 19). VajraSpy – An Android RAT. Retrieved November 5, 2025.

    Open source URL
  4. [4]
    mitre-attackS9006
    Open source URL
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.