MoqHao evolution: New variants start automatically right after installation
ID: 21b0a937-d648-510c-945a-9ceebd98fcfb
STIX ID: report--21b0a937-d648-510c-945a-9ceebd98fcfb
Feed Name: McAfee Labs Blog
> McAfee analysis of the MoqHao (Roaming Mantis) Android malware describes an active smishing campaign that installs apps which auto-execute without user launch, abuses Android install-time uniqueness checks and Unicode app names to evade detection, uses social engineering to set default SMS handling, retrieves phishing content from Pinterest, communicates with a WebSocket C2 offering extensive commands (exfiltrate SMS/contacts/photos, control device state), and includes multiple SHA256 and package-name IOCs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
