logo

The Mobile Malware Chronicles: Necro.N

ID: d693efda-5654-5cb1-b4a7-144e109171da

STIX ID: report--d693efda-5654-5cb1-b4a7-144e109171da

Feed Name: Zimperium Blog

Threat Score
70/100

Date Published: 2023-11-08

Date Updated: 2026-05-01

...
...

**Executive Summary:** zLabs tracked the Necro.N mobile malware campaign (37 samples) that uses a malicious advertising SDK embedding native libraries (libcoral.so, libsvm.so) which contact a C2 to retrieve steganographically-hidden DEX payloads; the malware can install apps, execute JS in invisible WebViews to subscribe victims to paid services, persist via boot receivers, access notifications and device identifiers, and shows low detection rates for some samples, indicating an active, evasive threat.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.