MobiDash internals: ghost clicks and SSH tunnels in commercial adware
ID: 87a81969-1d7e-5cad-86f9-c444a473fdcd
STIX ID: report--87a81969-1d7e-5cad-86f9-c444a473fdcd
Feed Name: Jamf Blog
This report analyzes the MobiDash Android adware family: a sophisticated repackaging/injection framework that embeds into legitimate APKs to perform stealthy ad fraud via scripted WebView interactions (synthetic MotionEvent), virtual/offscreen rendering, per-banner proxying (reverse SSH/SOCKS5) for geo-spoofing or bandwidth resale, and dynamic code/config delivery via InMemoryDexClassLoader; it includes anti-analysis checks, ad-SDK identity spoofing, and IOCs and remediation guidance for enterprise defenders.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
