Analysis Report on AI-Based Obfuscated Malicious Apps Using Compromised Legitimate Websites as C2 Servers
ID: 622484df-756b-53d3-9bbc-6d31f94e591d
STIX ID: report--622484df-756b-53d3-9bbc-6d31f94e591d
Feed Name: ASEC
Threat Score
This report analyzes a malicious Android APK distributed as a fake Korean delivery app that requests permissions, displays legitimate-looking tracking pages, and performs information theft. The malware employs ProGuard obfuscation (with Korean-named symbols) — potentially augmented by AI — and uses breached legitimate websites and a portal-hosted blog as hardcoded C2/exfiltration endpoints; the report includes MD5 hashes and URLs as IOCs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
