New Android Spyware Disguised as an Antivirus Attacking Business Executives
ID: a914497f-0c3c-5e5d-8f77-ddbfe7383e83
STIX ID: report--a914497f-0c3c-5e5d-8f77-ddbfe7383e83
Feed Name: cybersecurityNews.com
**Android.Backdoor.916.origin ("GuardCB")**: A malicious Android backdoor disguised as an antivirus app and distributed via sideloaded APKs in encrypted messenger threads targeting Russian business executives. Once installed it requests extensive permissions and Accessibility Service privileges to achieve persistence and self-restart, enabling operators to exfiltrate call logs, SMS, contacts, geolocation, images, microphone audio, camera video and screen captures, execute arbitrary shell commands, and resist removal via overlays and admin controls; Dr.Web researchers report active targeted campaigns and list detection/removal of known variants.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
