logo

Clever Billing Fraud Applications on Google Play: Etinu

ID: 00e8d33a-22b4-58ff-8f31-b2402f53e0ab

STIX ID: report--00e8d33a-22b4-58ff-8f31-b2402f53e0ab

Feed Name: McAfee Labs Blog

Threat Score
75/100

Date Published: 2021-04-19

Date Updated: 2026-04-28

Author: McAfee Labs

...
...

McAfee Mobile Research reports a large-scale Android malware campaign (Android/Etinu) that slipped malicious updates into otherwise benign apps on Google Play, achieving over 700,000 downloads; the malware uses encrypted payloads and dynamic code loading, contacts key-management C2s, abuses the Android Notification Listener to capture SMS messages without SMS-read permission, and uses WebView JavaScript to perform unauthorized premium subscription transactions — the report includes technical analysis, IOCs (file hashes, package names, and CloudFront URLs), and mitigation advice.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.