Mandrake spyware sneaks onto Google Play again, flying under the radar for two years
ID: 03665ae1-e0a0-56eb-8522-560b829cab04
STIX ID: report--03665ae1-e0a0-56eb-8522-560b829cab04
Feed Name: Securelist by Kaspersky
Kaspersky analyzed a resurgence of the Mandrake Android spyware on Google Play (2022–2024), finding five apps with >32,000 installs that used heavy native-library obfuscation (OLLVM), certificate-pinned C2, extensive sandbox/Frida/root checks, and multistage delivery (dropper → loader → core). The malware exfiltrates device and account data, can install additional APKs, and supports VNC-like remote webview control and screen recording; the report includes technical details, C2 protocol opcodes, IOCs (file hashes, domains, IPs), and attribution consistent with prior Mandrake activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
