'Snowblind' Tampering Technique May Drive Android Users Adrift
ID: 2be7b84e-8e78-5302-9e8f-05447ae5f2bf
STIX ID: report--2be7b84e-8e78-5302-9e8f-05447ae5f2bf
Feed Name: Dark Reading
Threat Score
Snowblind is a sophisticated Android banking Trojan observed in Southeast Asia that repackages apps with a native library leveraging seccomp filters to intercept and modify system calls, effectively hiding tampering checks and enabling credential and 2FA theft; distribution appears to rely on repackaged APKs and social engineering outside official stores, and defenders are advised to harden app distribution and detection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
