Malware attack on both Windows and Android
ID: 5fcd761a-f0b0-54f4-bb0e-7959831cafaa
STIX ID: report--5fcd761a-f0b0-54f4-bb0e-7959831cafaa
Feed Name: CERT Polska
Threat Score
A phishing campaign spoofing Poczta Polska delivers a dual-platform threat: a Windows TorrentLocker ransomware executable that encrypts files and demands ~1.47546 BTC, and an Android APK that obtains device-admin privileges, intercepts and forges SMS (including OTPs), performs overlay-based credential/phishing attacks against banking and Google Play, and accepts remote SMS/C2 commands; the report includes behavior details, attack flow, and MD5 indicators for the samples.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
