logo

NCSC-MAR-Infamous-Chisel.pdf

ID: 6245bdfd-422d-4bb2-9722-1ec463319998

STIX ID: report--6245bdfd-422d-4bb2-9722-1ec463319998

Threat Score

90/100

Uploaded: 2026-08-14

Published Date: 2023-08-30

Last Modified Date: 2023-08-30

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Infamous Chisel is a suite of Android malware attributed to the Sandworm group that enables persistent root execution by replacing /system/bin/netd, configures a Tor hidden service to provide SSH/SCP access (using modified Dropbear), and periodically collects and exfiltrates system, application and military-specific files and network reconnaissance data; the report includes detailed component descriptions, file hashes, file paths, YARA rules and detection guidance.