logo

'Snowblind' Tampering Technique May Drive Android Users Adrift

ID: 2be7b84e-8e78-5302-9e8f-05447ae5f2bf

STIX ID: report--2be7b84e-8e78-5302-9e8f-05447ae5f2bf

Feed Name: Dark Reading

Threat Score
74/100

Date Published: 2024-06-26

Date Updated: 2026-04-21

Author: Nate Nelson, Contributing Writer

...
...

Snowblind is a sophisticated Android banking Trojan observed in Southeast Asia that repackages apps with a native library leveraging seccomp filters to intercept and modify system calls, effectively hiding tampering checks and enabling credential and 2FA theft; distribution appears to rely on repackaged APKs and social engineering outside official stores, and defenders are advised to harden app distribution and detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.