logo

11,000 Android Devices Hacked by Chinese Threats Actors to Deploy PlayPraetor Malware

ID: 3baea261-d62c-5680-9d94-3550d8728f62

STIX ID: report--3baea261-d62c-5680-9d94-3550d8728f62

Feed Name: cybersecurityNews.com

Threat Score
78/100

Date Published: 2025-08-02

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

PlayPraetor is a sophisticated Android Remote Access Trojan deployed via fake Google Play pages that has infected over 11,000 devices and is expanding rapidly (~2,000 new infections/week). The malware abuses Android Accessibility Services to perform real-time fraudulent transactions against ~200 banking and crypto wallet apps, uses a three-tier C2 architecture (HTTP/HTTPS endpoints, persistent WebSocket on port 8282, and RTMP on port 1935), and is operated through a Chinese-language, multi-tenant control panel with major impact in Europe (58%) and notable presence in Africa, the Americas, and Asia.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.