RedAlert Trojan Campaign: Fake Emergency Alert App Spread via SMS Spoofing Israeli Home Front Command
ID: b0ff627e-9da5-5da4-9eeb-1cdff4474e48
STIX ID: report--b0ff627e-9da5-5da4-9eeb-1cdff4474e48
Feed Name: CloudSEK Blog
A targeted mobile espionage campaign distributes a trojanized 'RedAlert' Android app via smishing to exploit wartime panic; the loader spoofs signatures and installer provenance, dynamically loads a hidden payload (umgdn), and exfiltrates SMS, contacts and real-time GPS to attacker C2 (multiple IPs/domains via Cloudflare/AWS). The report includes static and dynamic analysis, IOCs (file hashes, IPs, URLs), impact assessment (weaponization of location data and 2FA bypass risk), and mitigation guidance including device quarantine, factory reset, MDM controls and network blocking.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
