Gold Open Source
ExplorePackagesVulnerabilitiesCWEsMCP ServersScan
Login
Gold Open Source

The authoritative source for production-ready open-source components. Every package, container image, AI model, and MCP server undergoes rigorous verification for security, malware, and license compliance.

Explore Gold

  • Explore Everything
  • Packages
  • Gold Certified Packages
  • Container Images
  • AI Models
  • MCP Servers
  • Agent Skills
  • Chip Manufacturers

Security Data & Tools

  • Scan Your Dependencies
  • Trending Threats
  • Threat RSS Feeds
  • CVE Database
  • Actively Exploited (KEV)
  • SGZ Zero-Days
  • CWE Index
  • MITRE ATT&CK
  • Malicious Packages
  • Security Glossary
  • Supply-Chain Report
  • Developers (API & Badge)
  • Chrome Extension
  • Credits & Data Sources

Products

  • The Platform
  • ESSCM
  • Portal
  • TPRM
  • OSM
  • Cowork
  • Code / Runner
  • Guard

Use Cases

  • Know Your Software
  • Auto-Fix Vulnerabilities
  • Asset Discovery
  • AI Governance
  • MCP Server Security
  • Supply Chain Compliance
  • Zero-Day Discovery
  • All Use Cases

Company

  • About
  • Pricing
  • Blog
  • Documentation
  • Safeguard Academy
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 Gold Open Source. All rights reserved.

Built with care bySafeguard
Home/ATT&CK/Software/S1094
MITRE ATT&CK Malware

BRATA (S1094)

ShareXLinkedInRedditHN

[BRATA](https://attack.mitre.org/software/S1094) (Brazilian Remote Access Tool, Android), is an evolving Android malware strain, detected in late 2018 and again in late 2021. Originating in Brazil, [BRATA](https://attack.mitre.org/software/S1094) was later also found in the UK, Poland, Italy, Spain, and USA, where it is believed to have targeted financial institutions such as banks. There are currently three known variants of [BRATA](https://attack.mitre.org/software/S1094).(Citation: securelist_brata_0819)(Citation: cleafy_brata_0122)(Citation: mcafee_brata_0421)

Platforms: Android

▪Techniques implemented (27)

T1407Download New Code at RuntimeT1430Location TrackingT1630.001Uninstall Malicious ApplicationT1513Screen CaptureT1461Lockscreen BypassT1662Data DestructionT1417.001KeyloggingT1641.001Transmitted Data ManipulationT1426System Information DiscoveryT1406Obfuscated Files or InformationT1629.003Disable or Modify ToolsT1627.001GeofencingT1418.001Security Software DiscoveryT1633.001System ChecksT1616Call ControlT1646Exfiltration Over C2 ChannelT1655.001Match Legitimate Name or LocationT1628.002User EvasionT1437.001Web ProtocolsT1516Input InjectionT1532Archive Collected DataT1663Remote Access SoftwareT1664Exploitation for Initial AccessT1417.002GUI Input CaptureT1660PhishingT1533Data from Local SystemT1406.002Software Packing
S1094on MITRE ATT&CK →

MITRE ATT&CK® is a registered trademark of The MITRE Corporation. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.