DocSwap Malware as Security Document Viewer Attacking Android Users Worldwide
ID: 93786fbf-51b8-5b27-8a21-1c4cc8fd8cbf
STIX ID: report--93786fbf-51b8-5b27-8a21-1c4cc8fd8cbf
Feed Name: cybersecurityNews.com
DocSwap is a sophisticated Android malware campaign masquerading as a legitimate document viewer to trick users into installing it; after installation it requests extensive permissions, persists on devices, uses obfuscation and a delayed multi-stage dropper, connects to encrypted C2 servers, and exfiltrates device info, contacts and SMS—capable of intercepting authentication messages and undermining 2FA. Analysts reported infection spikes across Asia, Europe and North America and recommend removing suspicious document apps, running full device scans with reputable AV, enabling Google Play Protect, and avoiding apps from unknown sources.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
