Fake Google Play Store Pages Used to Spread Android Malware – Stay Alert!
ID: 18bc44f9-d0dc-5de5-b3bc-f562ee2e361f
STIX ID: report--18bc44f9-d0dc-5de5-b3bc-f562ee2e361f
Feed Name: Cyber Press
### Executive Summary Researchers have observed a renewed campaign distributing the SpyNote Android RAT by hosting realistic fake Google Play Store pages that deliver a dropper APK. The dropper decrypts and loads the RAT via DEX injection, abuses Accessibility Services for persistence and stealth, intercepts SMS/2FA, records calls, logs keystrokes, and enables remote device control; analysts recovered C2 infrastructure (e.g., 154.90.58.26, 199.247.6.61) and multiple malicious domains, and warn users to avoid installing APKs from untrusted sources.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
