Skip to content

Threat actor

LianSpy

Last fetched

LianSpy is a threat actor tracked in WhisperGraph's MITRE ATT&CK corpus, observed using 0 techniques.

Description

LianSpy disguises itself as system applications or financial services like the Alipay digital payments app. When the spyware operates as a system app, it automatically gains the necessary permissions for further exploitation, requesting access to screen overlay, notifications, background activity, contacts, and call logs. Once activated, LianSpy hides its icon from the home screen and runs silently in the background with administrator privileges. It discreetly monitors user activity by intercepting call logs, sending a list of installed applications to the attackers' server, and recording the smartphone's screen, particularly during messaging activities. According to researchers, LianSpy is a post-exploitation malware, indicating that the attackers either exploited an unknown vulnerability in Android devices or gained physical access to the victims' smartphones to modify the firmware.

Techniques by tactic

No ATT&CK techniques are recorded for LianSpy in WhisperGraph.

Attributed infrastructure

None published. WhisperGraph carries no ATTRIBUTED_TO edge to LianSpy today — this states the absence of a published link, not that LianSpy has no infrastructure.

References

© The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.

Related pages

Pivot from LianSpy into its techniques, tactics and any attributed infrastructure.

Queries

Resolves the slug to this actor, merging every duplicate node sharing the same name.


MATCH (a:ACTOR)
WHERE a.name =~ $pattern OR any(x IN a.aliases WHERE x =~ $pattern)
RETURN a.id AS id, a.name AS name, a.aliases AS aliases, a.description AS description,
       a.references AS references, a.campaigns AS campaigns
LIMIT 25
Run yourself →

Techniques this actor uses, grouped by the tactic each one serves.


MATCH (a:ACTOR {name: $name})-[:USES_TECHNIQUE]->(t:ATTACK_PATTERN)
OPTIONAL MATCH (t)-[:USES_TACTIC]->(tac:ATTACK_PATTERN)
RETURN t.id AS techniqueId, t.name AS techniqueName, tac.id AS tacticId, tac.name AS tacticName
LIMIT 1000
Run yourself →

Infrastructure publicly attributed to this actor.


MATCH (n)-[:ATTRIBUTED_TO]->(a:ACTOR {name: $name})
RETURN labels(n)[0] AS kind, n.name AS name
LIMIT 25
Run yourself →

Or query Whisper from your own LLM workflow via the Whisper MCP server.