Fake Security App Found Abuses Japanese Payment System
ID: 797a1383-99da-593a-9e50-ad2902c27d24
STIX ID: report--797a1383-99da-593a-9e50-ad2902c27d24
Feed Name: McAfee Labs Blog
McAfee Mobile Research analyzed an Android malware campaign (detected as Android/ProxySpy) targeting mobile payment users in Japan that was distributed via Google Play, Google Drive links, and SMS lures; the malicious apps collect payment 'Service' passwords and phone/network info and implement a WAMP-over-WebSocket C2 with reverse-proxy capabilities allowing attackers to perform fraudulent transactions via victims' networks. The report includes technical details (native Golang library libmyapp.so, RPC commands like connect_to and toggle_wifi), screenshots, and IoCs (multiple SHA256s, IPs, and domain), and notes Google removed the apps after notification.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
