Android XLoader malware can now auto-execute after installation
ID: ceaf70a6-226c-59ad-8f4c-176aa4882c65
STIX ID: report--ceaf70a6-226c-59ad-8f4c-176aa4882c65
Feed Name: Bleeping Computer
A new XLoader (MoqHao) Android malware variant operated by the financially motivated Roaming Mantis group has evolved to auto-execute immediately after installation, enabling stealthy background operation. Distributed via SMS-linked APKs and disguised as Chrome using Unicode obfuscation, it requests dangerous permissions (SMS access, background exclusion, default SMS app) and can exfiltrate photos, SMS, contacts, device identifiers, and execute 20 C2 commands; researchers note use of Pinterest-hosted phishing content and advise scanning with security products while Google Play Protect provides protection on devices with Play Services.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
