Threat Research: FalseGuide
ID: 4fcaec4d-6993-529f-bbbb-bad5de87eea6
STIX ID: report--4fcaec4d-6993-529f-bbbb-bad5de87eea6
Feed Name: Zimperium Blog
FalseGuide is Android malware hidden in over 40 game-guide apps on Google Play since February 2017, estimated to have infected ~600,000 devices. The malware requests device-admin privileges to resist removal, subscribes to Firebase Cloud Messaging topics to receive commands and modules, runs a background service to display persistent pop-up ads, and can form a silent adware botnet with potential to enable rooting or conduct DDoS; infected apps were repeatedly removed from the store and zIPS is described as detecting and uninstalling these apps. Threat level: Low.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
