11,000 Android Devices Compromised by Chinese Threat Actors to Deploy PlayPraetor Malware
ID: e391c4f9-218d-5d26-aaad-7f88e37edb88
STIX ID: report--e391c4f9-218d-5d26-aaad-7f88e37edb88
Feed Name: Cyber Press
**PlayPraetor Android RAT (Executive Summary)**: PlayPraetor is a MaaS Android Remote Access Trojan that has infected over 11,000 devices in under three months and is expanding by ~2,000 new infections weekly; it leverages a Chinese-language multi-tenant C2 panel and automated phishing pages to target banking customers (notably in Europe—Portugal, Spain, France—and hotspots like Morocco, Peru, and Hong Kong), abuses Android Accessibility Services for full device takeover (credential/SMS theft, screen streaming), and includes published IOCs (sample hashes, domains, IP) for detection and blocking.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
