MiningDropper Spreads Infostealers, RATs, Banking Malware on Android
ID: 3d3796a1-8c9f-5262-b715-1113a34c9794
STIX ID: report--3d3796a1-8c9f-5262-b715-1113a34c9794
Feed Name: GBHackers
MiningDropper is a sophisticated, multi-stage Android dropper framework distributed via trojanized apps and phishing links that first loads XOR-obfuscated native code to decrypt staged DEX payloads and then installs crypto miners or high-impact user payloads (infostealers, BTMOB RAT, banking trojans). The report details obfuscation (XOR, AES, dynamic DEX), anti-emulation checks, split-APK reconstruction, campaign targeting (India, Asia, Europe, LATAM), and telemetry of over 1,500 low-AV-detected samples, underscoring active, large-scale abuse and the need for behavioral detection and MDM controls.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
