New Advanced Android Malware Posing as “System Update"
ID: 3bf432a8-8b18-5c0d-8802-ae6f23935d5e
STIX ID: report--3bf432a8-8b18-5c0d-8802-ae6f23935d5e
Feed Name: Zimperium Blog
**Executive summary:** Zimperium zLabs discovered a sophisticated Android spyware campaign distributed outside Google Play as a fake "System Update" app that functions as a RAT to collect and exfiltrate extensive personal data (messages, call/audio recordings, contacts, SMS, photos/videos thumbnails, browser bookmarks/searches, files, GPS, clipboard, device info). The malware uses Firebase Cloud Messaging for command-and-control and a separate C2 server for encrypted data uploads, abuses Accessibility Services and optional root access to steal WhatsApp data, schedules jobs, evades battery optimization, hides its icon, and includes provided IOCs (file hash and C2 URLs).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
