logo

Social Network Account Stealers Hidden in Android Gaming Hacking Tool

ID: a88ea942-617c-5050-8f56-1896ad465dd0

STIX ID: report--a88ea942-617c-5050-8f56-1896ad465dd0

Feed Name: McAfee Labs Blog

Threat Score
70/100

Date Published: 2021-10-19

Date Updated: 2026-04-28

Author: McAfee Labs

...
...

McAfee researchers discovered an Android credential-stealing campaign packaged as a modified PUBG game assistant (‘DesiEsp’) distributed via Telegram; the malware requests superuser and AccessibilityService/device-admin privileges to access system and app account databases, monitor login fields, install a disguised payload, and exfiltrate Google, Facebook, Twitter, Telegram, and PUBG account credentials. McAfee provides multiple dropper and payload sample hashes and a malicious domain (hosting-b5476.gq) as indicators of compromise and notes infections primarily in the United States, India, and Saudi Arabia.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.