Currently viewing ATT&CK v7.2 which was live between July 8, 2020 and October 26, 2020. Learn more about the versioning system or see the live site.
Register to stream the next session of ATT&CKcon Power Hour November 12


ShiftyBug is an auto-rooting adware family of malware for Android. The family is very similar to the other Android families known as Shedun, Shuanet, Kemoge, though it is not believed all the families were created by the same group. [1]

ID: S0294
Platforms: Android
Version: 1.1
Created: 25 October 2017
Last Modified: 11 December 2018

Techniques Used

Domain ID Name Use
Mobile T1404 Exploit OS Vulnerability

ShiftyBug is packed with at least eight publicly available exploits that can perform rooting.[1]

Mobile T1400 Modify System Partition

ShiftyBug is auto-rooting adware that embeds itself as a system application, making it nearly impossible to remove.[1]
