Social Network Account Stealers Hidden in Android Gaming Hacking Tool
ID: a88ea942-617c-5050-8f56-1896ad465dd0
STIX ID: report--a88ea942-617c-5050-8f56-1896ad465dd0
Feed Name: McAfee Labs Blog
McAfee researchers discovered an Android credential-stealing campaign packaged as a modified PUBG game assistant (‘DesiEsp’) distributed via Telegram; the malware requests superuser and AccessibilityService/device-admin privileges to access system and app account databases, monitor login fields, install a disguised payload, and exfiltrate Google, Facebook, Twitter, Telegram, and PUBG account credentials. McAfee provides multiple dropper and payload sample hashes and a malicious domain (hosting-b5476.gq) as indicators of compromise and notes infections primarily in the United States, India, and Saudi Arabia.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
