Android Malware Campaign Uses Fake Document Reader App with 100K Google Play Downloads
ID: 9ab2ec88-f4b5-5775-9777-fc6d80a4a12e
STIX ID: report--9ab2ec88-f4b5-5775-9777-fc6d80a4a12e
Feed Name: GBHackers
A fake document-reader app on Google Play was used as a dropper to distribute the Anatsa banking trojan, reaching roughly 100K installs before a malicious update fetched and installed the payload; the report includes IOCs (installer MD5 f72b1a333fa28b133df6476561142d6a, payload MD5 61d25684e6f42e386f40ee60f5c54dca, C2 endpoints http://162.252.173.37:85/api and http://66.206.6.6:8080/disclaimer.txt, and package name com.westhorizont.appsforge.filehorizon_explorereaddocuments) and recommends inventorying recent document/file apps, checking telemetry and DNS logs, and verifying against silent APK downloads.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
