New LianSpy malware hides by blocking Android security feature
ID: 6d1b9e65-2750-5cc4-b516-523c936c2efe
STIX ID: report--6d1b9e65-2750-5cc4-b516-523c936c2efe
Feed Name: Bleeping Computer
Kaspersky researchers uncovered LianSpy, a previously undocumented Android spyware active since July 2021 that poses as Alipay or a system service to evade detection, gains root via a modified su/mu binary (likely via a zero-day or physical access), bypasses Android 12+ privacy indicators, suppresses user notifications, captures screenshots and other sensitive data from targeted apps, stores data encrypted locally, and exfiltrates it to Yandex Disk under attacker control; the malware is highly stealthy and focused on Russian targets.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
