SoumniBot malware exploits Android bugs to evade detection
ID: 38ab6140-03d3-5256-bdf9-3ed4faf28565
STIX ID: report--38ab6140-03d3-5256-bdf9-3ed4faf28565
Feed Name: Bleeping Computer
A Kaspersky analysis describes SoumniBot, an Android banking malware that exploits weaknesses in Android's APK manifest parsing (invalid compression flags, misreported file sizes, and overly long XML namespace strings) to evade analysis and security tooling. Once installed—primarily targeting Korean users and likely delivered via third-party stores or malicious updates—the malware retrieves configuration from hardcoded servers, persistently runs background services, exfiltrates sensitive data (contacts, SMS, photos, banking certificates, IP and carrier info) via MQTT commands, and supports remote actions like SMS forwarding and contact manipulation; Kaspersky provides hashes and domain IOCs and has notified Google.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
