Snowblind malware abuses Android security feature to bypass security
ID: 4e3fb4d4-9997-526e-9794-fe736f315e76
STIX ID: report--4e3fb4d4-9997-526e-9794-fe736f315e76
Feed Name: Bleeping Computer
Threat Score
Snowblind is a novel Android malware that abuses the Linux seccomp mechanism to intercept and modify system calls (for example open()), trigger SIGSYS, and handle that signal to make anti-tampering checks read an unmodified APK. Promon observed the technique in an attack against an i‑Sprint customer in Southeast Asia; the method enables credential theft, remote control and bypassing of security features with minimal performance impact and could be adopted by other attackers.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
