logo

Fake Google Play Store Pages Used to Spread Android Malware – Stay Alert!

ID: 18bc44f9-d0dc-5de5-b3bc-f562ee2e361f

STIX ID: report--18bc44f9-d0dc-5de5-b3bc-f562ee2e361f

Feed Name: Cyber Press

Threat Score
70/100

Date Published: 2025-08-25

Date Updated: 2026-04-19

Author: Priya

...
...

### Executive Summary Researchers have observed a renewed campaign distributing the SpyNote Android RAT by hosting realistic fake Google Play Store pages that deliver a dropper APK. The dropper decrypts and loads the RAT via DEX injection, abuses Accessibility Services for persistence and stealth, intercepts SMS/2FA, records calls, logs keystrokes, and enables remote device control; analysts recovered C2 infrastructure (e.g., 154.90.58.26, 199.247.6.61) and multiple malicious domains, and warn users to avoid installing APKs from untrusted sources.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.