Android.Phantom trojans are bundled with modded games and popular apps to infiltrate smartphones. They use machine learning and video broadcasts to engage in click fraud
ID: 87e5812f-c3c4-5fa0-9b18-244447c6618e
STIX ID: report--87e5812f-c3c4-5fa0-9b18-244447c6618e
Feed Name: Dr.Web News
Threat Score
Researchers at Doctor Web uncovered the Android.Phantom trojan family embedded into legitimate and modified Android apps (notably via Xiaomi GetApps and modded APK sites/Telegram/Discord), executing large-scale click-fraud using WebView automation, TensorFlowJS image analysis, and WebRTC-based remote control, with additional dropper modules and spyware exfiltrating device data; tens of thousands of app downloads indicate active distribution and significant risk to users.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
