logo

MalBus Actor Changed Market from Google Play to ONE Store

ID: acdb1c9e-840f-5d8d-85f7-cf630a0f4b67

STIX ID: report--acdb1c9e-840f-5d8d-85f7-cf630a0f4b67

Feed Name: McAfee Labs Blog

Threat Score
70/100

Date Published: 2020-04-09

Date Updated: 2026-04-28

Author: McAfee Labs

...
...

McAfee Mobile Research details a MalBus Android malware variant distributed through South Korea's ONE Store (and also via Google Play) that uses an embedded downloader (libmovie.so) to fetch RC4-encrypted ELF payloads, dynamically load native libraries, and provide C2-driven functions including SMS/MMS capture, local TCP control on port 1111, and runtime loading of updated native modules; the report includes observed infected app versions, behavioral analysis, and multiple SHA-256 hashes for the APKs and payloads.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.