Android SpyNote attacks electric and water public utility users in Japan
ID: a40c032d-20eb-50d1-9969-28c7aa4d2d66
STIX ID: report--a40c032d-20eb-50d1-9969-28c7aa4d2d66
Feed Name: McAfee Labs Blog
McAfee Mobile observed a June 7, 2023 smishing campaign targeting Japanese Android users by impersonating power and water utilities to trick victims into downloading SpyNote RAT from a phishing site; the malware abuses Accessibility and device-admin privileges to persist and steal location, contacts, SMS/calls, and two-factor authentication tokens. The report includes multiple SHA256 hashes, package names, screenshots of the phishing flow and fake settings screens, and notes McAfee detection as Android/SpyNote.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
