MalBus Actor Changed Market from Google Play to ONE Store
ID: acdb1c9e-840f-5d8d-85f7-cf630a0f4b67
STIX ID: report--acdb1c9e-840f-5d8d-85f7-cf630a0f4b67
Feed Name: McAfee Labs Blog
McAfee Mobile Research details a MalBus Android malware variant distributed through South Korea's ONE Store (and also via Google Play) that uses an embedded downloader (libmovie.so) to fetch RC4-encrypted ELF payloads, dynamically load native libraries, and provide C2-driven functions including SMS/MMS capture, local TCP control on port 1111, and runtime loading of updated native modules; the report includes observed infected app versions, behavioral analysis, and multiple SHA-256 hashes for the APKs and payloads.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
