Clever Billing Fraud Applications on Google Play: Etinu
ID: 00e8d33a-22b4-58ff-8f31-b2402f53e0ab
STIX ID: report--00e8d33a-22b4-58ff-8f31-b2402f53e0ab
Feed Name: McAfee Labs Blog
McAfee Mobile Research reports a large-scale Android malware campaign (Android/Etinu) that slipped malicious updates into otherwise benign apps on Google Play, achieving over 700,000 downloads; the malware uses encrypted payloads and dynamic code loading, contacts key-management C2s, abuses the Android Notification Listener to capture SMS messages without SMS-read permission, and uses WebView JavaScript to perform unauthorized premium subscription transactions — the report includes technical analysis, IOCs (file hashes, package names, and CloudFront URLs), and mitigation advice.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
