Instagram credentials Stealer: Disguised as Mod App
ID: e6ebd464-4c13-5056-99f3-6fbc8a28f780
STIX ID: report--e6ebd464-4c13-5056-99f3-6fbc8a28f780
Feed Name: McAfee Labs Blog
McAfee Mobile Research describes an Android credential-stealing malware that masquerades as the Instander Instagram mod to trick users into entering credentials, then exfiltrates those credentials by abusing Firebase's createUserWithEmailAndPassword API (combining user input with a static domain and password) and sending data in Protobuf format to www.googleapis.com; the report includes behavioral analysis, network observations, and an SHA256 sample identified as Android/InstaStealer.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
