NCSC-MAR-Infamous-Chisel.pdf
ID: 6245bdfd-422d-4bb2-9722-1ec463319998
STIX ID: report--6245bdfd-422d-4bb2-9722-1ec463319998
Threat Score
90/100
Uploaded: 2026-08-14
Published Date: 2023-08-30
Last Modified Date: 2023-08-30
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Infamous Chisel is a suite of Android malware attributed to the Sandworm group that enables persistent root execution by replacing /system/bin/netd, configures a Tor hidden service to provide SSH/SCP access (using modified Dropbear), and periodically collects and exfiltrates system, application and military-specific files and network reconnaissance data; the report includes detailed component descriptions, file hashes, file paths, YARA rules and detection guidance.
