Machine Learning vs Signatures, Round N: Once Again, Zimperium Detects Malware No One Else Does
ID: 956bbeb8-19fe-51b0-aab0-ff725edc4427
STIX ID: report--956bbeb8-19fe-51b0-aab0-ff725edc4427
Feed Name: Zimperium Blog
Zimperium zLabs describes an Android adware/click-fraud dropper campaign (e.g., com.xksx.tosiok) that dynamically downloads and decrypts plugin payloads to start advertising and statistics SDKs, collect device identifiers and geolocation, and launch targeted ads via abused legitimate apps; the report documents evasive techniques (reflection, obfuscated strings, encrypted DEX, manual service triggering), provides IOCs/hashes, and notes the campaign's active development and limited industry detection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
