logo

Analysis Report on AI-Based Obfuscated Malicious Apps Using Compromised Legitimate Websites as C2 Servers

ID: 622484df-756b-53d3-9bbc-6d31f94e591d

STIX ID: report--622484df-756b-53d3-9bbc-6d31f94e591d

Feed Name: ASEC

Threat Score
70/100

Date Published: 2025-11-17

Date Updated: 2026-04-26

Author: ATCP

...
...

This report analyzes a malicious Android APK distributed as a fake Korean delivery app that requests permissions, displays legitimate-looking tracking pages, and performs information theft. The malware employs ProGuard obfuscation (with Korean-named symbols) — potentially augmented by AI — and uses breached legitimate websites and a portal-hosted blog as hardcoded C2/exfiltration endpoints; the report includes MD5 hashes and URLs as IOCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.