New Octo Android malware version impersonates NordVPN, Google Chrome
ID: 1e2224ea-58eb-5eb6-b72f-1da62e833b06
STIX ID: report--1e2224ea-58eb-5eb6-b72f-1da62e833b06
Feed Name: Bleeping Computer
Threat Score
ThreatFabric has observed a new variant of the Octo Android banking trojan, dubbed “Octo2,” spreading in Europe via fake NordVPN, Google Chrome and a Europe Enterprise app; the variant adds native-code payload decryption, dynamic library loading, a DGA-based C2, improved evasion and a low-bandwidth RAT mode, and is being distributed via third-party app stores using Zombider sideloading, with observed operations in Italy, Poland, Moldova and Hungary.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
