Financially Motivated Mobile Scamware Exceeds 100M Installations
ID: ffc90b12-4734-5af2-9dc7-42e86494c9ac
STIX ID: report--ffc90b12-4734-5af2-9dc7-42e86494c9ac
Feed Name: Zimperium Blog
Zimperium zLabs documents the Dark Herring Android scamware campaign — a large-scale mobile fraud operation that distributed roughly 470 malicious apps (over 105M installs) to subscribe victims to premium services via Direct Carrier Billing. The report explains the app architecture (WebView-based first-stage URLs on CloudFront, JS-driven C2 and device identification), geo-targeted phishing webpages, global victim distribution across 70+ countries, identified IOCs (GitHub), and mitigation via Zimperium on-device protections; Google Play takedowns removed many apps but copies remain on third-party stores.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
