Cellik Android malware builds malicious versions from Google Play apps
ID: 8b35dd7e-a7be-5231-b3f9-1de3896c89a5
STIX ID: report--8b35dd7e-a7be-5231-b3f9-1de3896c89a5
Feed Name: Bleeping Computer
A new Android malware-as-a-service called Cellik is being sold on underground forums and advertises features to trojanize Google Play apps. It offers real-time screen streaming, notification interception, a hidden browser that can use stolen cookies, app injection/overlay attacks for credential theft, file exfiltration and device-wipe capabilities, and an APK builder that claims integration with Google Play to wrap malicious payloads in legitimate apps; Google reports no known Play Store infections at this time.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
