logo

Stealth Backdoor “Android/Xamalicious” Actively Infecting Devices

ID: 45e403e1-7b5e-5482-acd2-73772728964e

STIX ID: report--45e403e1-7b5e-5482-acd2-73772728964e

Feed Name: McAfee Labs Blog

Threat Score
78/100

Date Published: 2023-12-22

Date Updated: 2026-04-28

Author: McAfee Labs

...
...

McAfee Mobile Research documents Android/Xamalicious, a Xamarin-based Android backdoor that tricks users into granting Accessibility Services, communicates with a C2 using JWE/JWT and hardcoded RSA keys, and conditionally downloads an AES-encrypted second-stage DLL that can fully control devices to perform ad-fraud and other financially motivated actions; the campaign included ~25 malicious apps (some on Google Play) with estimated 327,000+ installs and detailed IoCs and package hashes.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.