logo

New Advanced Android Malware Posing as “System Update"

ID: 3bf432a8-8b18-5c0d-8802-ae6f23935d5e

STIX ID: report--3bf432a8-8b18-5c0d-8802-ae6f23935d5e

Feed Name: Zimperium Blog

Threat Score
78/100

Date Published: 2021-03-26

Date Updated: 2026-05-01

...
...

**Executive summary:** Zimperium zLabs discovered a sophisticated Android spyware campaign distributed outside Google Play as a fake "System Update" app that functions as a RAT to collect and exfiltrate extensive personal data (messages, call/audio recordings, contacts, SMS, photos/videos thumbnails, browser bookmarks/searches, files, GPS, clipboard, device info). The malware uses Firebase Cloud Messaging for command-and-control and a separate C2 server for encrypted data uploads, abuses Accessibility Services and optional root access to steal WhatsApp data, schedules jobs, evades battery optimization, hides its icon, and includes provided IOCs (file hash and C2 URLs).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.