logo

MoqHao Leverages iCloud and VK in Campaign Targeting Apple IDs and Android Device

ID: a40e9d10-1fcc-5f4b-9b36-b1ec5372d628

STIX ID: report--a40e9d10-1fcc-5f4b-9b36-b1ec5372d628

Feed Name: Hunt.io Blog

Threat Score
72/100

Date Published: 2026-02-16

Date Updated: 2026-04-28

...
...

This report analyzes a MoqHao (Wroba/XLoader) smishing campaign that uses localized Apple ID phishing pages and malicious Android APKs delivered via shortened URLs; attackers abuse dynamic DNS (DuckDNS), legitimate services (Apple iCloud hosting), and obfuscate C2 addresses via a VK profile while redirecting victims through multiple domains. The analysis includes a malicious APK SHA256, VirusTotal detections, redirect chains, C2 IPs/ASNs, and a table of network observables, and concludes with mitigation advice for mobile users.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.