Add Quark malware analysis report for Exodus - #976
Merged
Merged
Conversation
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## master #976 +/- ##
=======================================
Coverage 81.28% 81.28%
=======================================
Files 84 84
Lines 7923 7923
=======================================
Hits 6440 6440
Misses 1483 1483
Flags with carried forward coverage won't be shown. Click here to find out more. ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Exodus Malware Family Analysis Report
This report analyses the Exodus malware family using Quark's rule classification. Exodus is Android surveillanceware written by the Italian firm eSurv and documented by Security Without Borders in 2019. It was delivered through decoy apps posing as mobile-operator service tools, and installs in two stages: a first stage that registers the device with the operator's server, and a surveillance implant downloaded afterwards. The three samples analysed here are the first stage. This run added a new rule (#279), which flags reading the device IMEI and the subscriber IMSI in the same method; it is demonstrated in the T1422 section below. Check here for the rule details.
Quark's rule classification flagged 3 of 3 Exodus samples as high-risk in this experiment (detection rate 100%). Benign-cohort false-positive rate was not measured here. See tested APKs below.
Identified Well-Known Threats
This section uses MITRE ATT&CK Mobile as its reference taxonomy, anchored to the S0405 Exodus software entry. Of the 19 techniques documented for the family, Quark's static bytecode analysis confirms the 3 listed below; see the coverage-gap notes at the end of this section for the other 16.
All behavior maps below were rendered from sample
4f6146956b50ae3a6e80a1c1f771dba848ba677064eb0e166df5804ac2766898.apk(packageoperatore.italia, posing as an Italian operator's contact-sync app) — chosen as the representative sample whose detected behaviors most fully cover the documented profile of Exodus. The other 2 family samples were used to compute the detection-rate figure above.Each section below corresponds to one technique from the table above. Within each section we first quote the MITRE definition, then show the Quark behavior map extracted from the representative sample's bytecode, then walk through the call sequence and list the underlying rules.
1. T1418 Software Discovery
T1418 Software Discovery — attack.mitre.org
Llib/operatore/core/a;awalks the fullgetInstalledApplicationslist and compares each package name against the one it is looking for. Its caller uses that answer to decide whether to start the registration routine.Behaviors detected by Quark:
2. T1422 System Network Configuration Discovery
T1422 System Network Configuration Discovery — attack.mitre.org
Llib/operatore/core/b;creads the device IMEI and the subscriber IMSI in one method, along with the network operator name. This is the method that registers the device with the server, and the new rule added by this run fires on the IMEI-and-IMSI pair.Behaviors detected by Quark:
3. T1636.002 Call Log
T1636.002 Call Log — attack.mitre.org
Loperatore/italia/ProgressActivity$2;aqueries the call-log content provider while the decoy "optimisation" screen runs. It takes the number of rows from the cursor; the call records themselves are not read out here.Behaviors detected by Quark:
Coverage-gap notes
The 16 MITRE techniques documented for Exodus that this report does NOT demonstrate, grouped by the reason Quark could not confirm them on these samples:
The behaviour belongs to the second stage, which these samples only download (10) — T1421 System Network Connections Discovery, T1422.001 Internet Connection Discovery, T1429 Audio Capture, T1430 Location Tracking, T1512 Video Capture, T1513 Screen Capture, T1532 Archive Collected Data, T1636.001 Calendar Entries, T1636.003 Contact List and T1636.004 SMS Messages. Rules for location, screen capture, calendar reads, SMS reads and network-state checks do fire in these APKs, but every one of them lands in the bundled AndroidX support or logback libraries, and none of those methods is reachable from Exodus's own code. The location hit is AppCompat's TwilightManager deciding whether to apply the night theme; the SMS-and-call-log hit is a support-library helper that reads a column from whatever content URI it is handed. Neither result reaches Exodus.
Quark reached Exodus's own code, but the primitive is not this technique (3) — T1404 Exploitation for Privilege Escalation, T1409 Stored Application Data and T1533 Data from Local System. The only
Runtime.execcalls in Exodus's own code runchmod 700over the files it has just unpacked, which makes the downloaded payload executable rather than exploiting anything. The file reads that matched T1409 and T1533 come from that same routine — Exodus reading back its own downloaded payload, not other applications' data. Quark reports all of it under one name,Llib/operatore/core/f;a, because three different methods in that class are calleda.The behaviour is real, but no rule covers the API it uses (3) — T1407 Download New Code at Runtime, T1437.001 Web Protocols and T1509 Non-Standard Port. Exodus downloads its second stage and talks to its server through OkHttp; the pool's HTTP rules match
HttpURLConnectionand Apache HttpClient, and none match OkHttp. This run did generate a candidate rule for the step that follows the download (Context.getFilesDirpaired withRuntime.exec), but it trained to a negative score — it also fires on benign apps — so it was not added. For T1509 there is nothing non-standard to find: the server is reached over HTTPS on port 443.List of Tested APKs
The table below lists the APKs we tested.
🤖 Generated with Claude Code