Scotch
Description
(Citizen Lab) The ultimate spyware tool deployed by MOONSHINE, Scotch, is a modular Java application which uses the WebSocket protocol to communicate with its C2 server. The Scotch payload itself has limited espionage features, such as obtaining device information and uploading files from the infected device. However, as part of its initial contact with the C2, Scotch downloads additional plugins. During our analysis, we were able to acquire two plugin packages, named “Bourbon.jar” and “IceCube.jar” which added functionality including exfiltrating SMS text messages, address books, and call logs, and spying on the target through their phone’s camera, microphone, and GPS.
Names
Name |
---|
Scotch |
Category
Malware
Type
- Reconnaissance
- Backdoor
- Info stealer
- Exfiltration
- Downloader
Information
Other Information
Uuid
8a258c41-a89e-44d0-b1e4-d27ed074cd21
Last Card Change
2020-04-20