The Mobile Malware Chronicles: Necro.N
ID: d693efda-5654-5cb1-b4a7-144e109171da
STIX ID: report--d693efda-5654-5cb1-b4a7-144e109171da
Feed Name: Zimperium Blog
**Executive Summary:** zLabs tracked the Necro.N mobile malware campaign (37 samples) that uses a malicious advertising SDK embedding native libraries (libcoral.so, libsvm.so) which contact a C2 to retrieve steganographically-hidden DEX payloads; the malware can install apps, execute JS in invisible WebViews to subscribe victims to paid services, persist via boot receivers, access notifications and device identifiers, and shows low detection rates for some samples, indicating an active, evasive threat.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
