Threat Research: zTorg Trojan Variations
ID: e4f554ae-719d-56e9-a6f4-8882ec73cc78
STIX ID: report--e4f554ae-719d-56e9-a6f4-8882ec73cc78
Feed Name: Zimperium Blog
Threat Score
This report documents two zTorg Android trojan variants found in Google Play that perform premium-rate SMS fraud and WAP billing abuse: they contact a C2, check IMSI/MCC/MNC to target operators, receive encrypted JSON with URLs or SMS commands that trigger costly SMS or billing pages, and employ stealth (muting device and deleting incoming SMS); detections by zIPS and Kaspersky are noted and the apps had tens of thousands of installs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
