SoumniBot: the new Android banker’s unique techniques
ID: 088ea9b4-e8e4-57cc-937c-9f258ec068ee
STIX ID: report--088ea9b4-e8e4-57cc-937c-9f258ec068ee
Feed Name: Securelist by Kaspersky
SoumniBot is an Android banking Trojan targeting Korean users that uses unconventional AndroidManifest obfuscation techniques (invalid ZIP compression method, incorrect manifest size with overlay, and overly long XML namespace names) to evade analysis and installation checks; it collects and exfiltrates sensitive data including SMS, contacts, media and Korean banking keys/certificates (NPKI/yessign), communicates with C2 via hardcoded mainsite and MQTT servers, and exposes multiple remote commands for data theft and device manipulation. Indicators include several MD5 hashes and C2 domains provided in the report.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
