MazarBOT is Android malware that was distributed via SMS in Denmark in 2016. [1]

ID: S0303
Platforms: Android
Version: 1.1
Created: 25 October 2017
Last Modified: 11 December 2018

Techniques Used

Domain ID Name Use
Mobile T1412 Capture SMS Messages

MazarBOT can intercept two-factor authentication codes sent by online banking apps.[1]

Mobile T1448 Carrier Billing Fraud

MazarBOT can send messages to premium-rate numbers.[1]

Mobile T1476 Deliver Malicious App via Other Means

MazarBOT is delivered via an unsolicited text message containing a link to a web download URI.[1]