More Than a Miner: The Evasive MiningDropper Framework Hijacking Android Worldwide
ID: 598bf0ee-9225-544f-b1f0-e46bcaf7424d
STIX ID: report--598bf0ee-9225-544f-b1f0-e46bcaf7424d
Feed Name: securityonline.info
A CRIL investigative report describes "MiningDropper", a sophisticated, modular Android malware distribution framework that uses XOR-based native obfuscation, AES-encrypted payload staging, dynamic DEX loading, memory-only deobfuscation, and anti-emulation to evade analysis. The framework can deliver a range of monetization payloads — from silent crypto miners to infostealers and the BTMOB RAT — and has been observed in active, regionally tailored campaigns targeting India and multiple global regions.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
