Gold Open Source
ExplorePackagesVulnerabilitiesCWEsMCP ServersScan
Login
Gold Open Source

The authoritative source for production-ready open-source components. Every package, container image, AI model, and MCP server undergoes rigorous verification for security, malware, and license compliance.

Explore Gold

  • Explore Everything
  • Packages
  • Gold Certified Packages
  • Container Images
  • AI Models
  • MCP Servers
  • Agent Skills
  • Chip Manufacturers

Security Data & Tools

  • Scan Your Dependencies
  • Trending Threats
  • Threat RSS Feeds
  • CVE Database
  • Actively Exploited (KEV)
  • SGZ Zero-Days
  • CWE Index
  • MITRE ATT&CK
  • Malicious Packages
  • Security Glossary
  • Supply-Chain Report
  • Developers (API & Badge)
  • Chrome Extension
  • Credits & Data Sources

Products

  • The Platform
  • ESSCM
  • Portal
  • TPRM
  • OSM
  • Cowork
  • Code / Runner
  • Guard

Use Cases

  • Know Your Software
  • Auto-Fix Vulnerabilities
  • Asset Discovery
  • AI Governance
  • MCP Server Security
  • Supply Chain Compliance
  • Zero-Day Discovery
  • All Use Cases

Company

  • About
  • Pricing
  • Blog
  • Documentation
  • Safeguard Academy
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 Gold Open Source. All rights reserved.

Built with care bySafeguard
Home/ATT&CK/Software/S0485
MITRE ATT&CK Malware

Mandrake (S0485)

oxidebriarricinusdarkmatter
ShareXLinkedInRedditHN

[Mandrake](https://attack.mitre.org/software/S0485) is a sophisticated Android espionage platform that has been active in the wild since at least 2016. [Mandrake](https://attack.mitre.org/software/S0485) is very actively maintained, with sophisticated features and attacks that are executed with surgical precision. [Mandrake](https://attack.mitre.org/software/S0485) has gone undetected for several years by providing legitimate, ad-free applications with social media and real reviews to back the apps. The malware is only activated when the operators issue a specific command.(Citation: Bitdefender Mandrake)

Platforms: Android

▪Techniques implemented (25)

T1655.001Match Legitimate Name or LocationT1636.003Contact ListT1633.001System ChecksT1517Access NotificationsT1541Foreground PersistenceT1409Stored Application DataT1509Non-Standard PortT1582SMS ControlT1513Screen CaptureT1629.003Disable or Modify ToolsT1406Obfuscated Files or InformationT1629.001Prevent Application RemovalT1481.002Bidirectional CommunicationT1516Input InjectionT1430Location TrackingT1418Software DiscoveryT1417.002GUI Input CaptureT1632.001Code Signing Policy ModificationT1628.001Suppress Application IconT1407Download New Code at RuntimeT1637.001Domain Generation AlgorithmsT1630.002File DeletionT1426System Information DiscoveryT1544Ingress Tool TransferT1636.004SMS Messages
S0485on MITRE ATT&CK →

MITRE ATT&CK® is a registered trademark of The MITRE Corporation. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.