logo

SoumniBot malware exploits Android bugs to evade detection

ID: 38ab6140-03d3-5256-bdf9-3ed4faf28565

STIX ID: report--38ab6140-03d3-5256-bdf9-3ed4faf28565

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2024-04-17

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

A Kaspersky analysis describes SoumniBot, an Android banking malware that exploits weaknesses in Android's APK manifest parsing (invalid compression flags, misreported file sizes, and overly long XML namespace strings) to evade analysis and security tooling. Once installed—primarily targeting Korean users and likely delivered via third-party stores or malicious updates—the malware retrieves configuration from hardcoded servers, persistently runs background services, exfiltrates sensitive data (contacts, SMS, photos, banking certificates, IP and carrier info) via MQTT commands, and supports remote actions like SMS forwarding and contact manipulation; Kaspersky provides hashes and domain IOCs and has notified Google.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.