logo

Zimperium Discovers MobOk Malware Left Undetected by AV Industry for Months

ID: 2a107a09-a9b3-5556-87dc-996f26f36a65

STIX ID: report--2a107a09-a9b3-5556-87dc-996f26f36a65

Feed Name: Zimperium Blog

Threat Score
70/100

Date Published: 2020-06-26

Date Updated: 2026-05-01

...
...

Zimperium zLabs reports on evolved MobOk Android malware variants distributed (including via Google Play) that hide malicious code with the Tencent packer and native libraries, steal SMS for 2FA bypass, abuse Accessibility Services to automate UI interactions and install companion apps, bypass image CAPTCHAs via external recognition services, subscribe victims to premium services, and provide detailed IOCs (file hashes and C2 URLs).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.