Necro malware continues to haunt side-loaders of dodgy Android mods
ID: 1cce5b1e-3e0e-5ef7-bd66-0c4b0e106582
STIX ID: report--1cce5b1e-3e0e-5ef7-bd66-0c4b0e106582
Feed Name: The Register (Security)
Kaspersky researchers have identified a resurgence of the Necro Android trojan distributing via spoofed/modded apps and some Play Store listings (e.g., Wuta Camera, Max Browser), potentially exposing millions of users; the trojan's primary impact is intrusive ads and fraudulent subscription charges, and the latest variant uses steganography (payload hidden in PNG images). Google removed known malicious app versions and Kaspersky published IOCs to aid detection and mitigation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
