logo

New Android Malware Campaigns Evading Detection Using Cross-Platform Framework .NET MAUI 

ID: d341e1e6-248b-5718-8157-7cceb882bb1d

STIX ID: report--d341e1e6-248b-5718-8157-7cceb882bb1d

Feed Name: McAfee Labs Blog

Threat Score
70/100

Date Published: 2025-03-25

Date Updated: 2026-04-28

Author: McAfee Labs

...
...

McAfee Mobile Research describes active Android malware campaigns built with .NET MAUI that hide malicious C# payloads in assembly blobs and use evasion techniques — including multi-stage dynamic loading, encrypted socket communication, and manifest manipulation — to steal banking credentials, contacts, SMS, and images from targeted users (notably Indian and Chinese-speaking audiences); the report includes technical findings, examples, and IOCs and recommends avoiding unofficial app stores and using up-to-date mobile security.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.