logo

Fake Security App Found Abuses Japanese Payment System

ID: 797a1383-99da-593a-9e50-ad2902c27d24

STIX ID: report--797a1383-99da-593a-9e50-ad2902c27d24

Feed Name: McAfee Labs Blog

Threat Score
75/100

Date Published: 2022-11-30

Date Updated: 2026-04-28

Author: McAfee Labs

...
...

McAfee Mobile Research analyzed an Android malware campaign (detected as Android/ProxySpy) targeting mobile payment users in Japan that was distributed via Google Play, Google Drive links, and SMS lures; the malicious apps collect payment 'Service' passwords and phone/network info and implement a WAMP-over-WebSocket C2 with reverse-proxy capabilities allowing attackers to perform fraudulent transactions via victims' networks. The report includes technical details (native Golang library libmyapp.so, RPC commands like connect_to and toggle_wifi), screenshots, and IoCs (multiple SHA256s, IPs, and domain), and notes Google removed the apps after notification.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.