Fake Porn Site Serving Chinese SMS Trojan
ID: 0bf48216-09b7-55b8-af99-2c2596e9434b
STIX ID: report--0bf48216-09b7-55b8-af99-2c2596e9434b
Feed Name: Zscaler Security Research Blog
Android SMS Trojan delivered via fake porn site and third-party distribution tricks users into installing dynamically named APKs, registers an SMS BroadcastReceiver to intercept and parse Chinese verification messages, generates and responds to premium-rate SMS to complete fraudulent purchases, and reports device data to C2 infrastructure (domain: msg-web.pw; IP: 115.28.252.178). The malware also downloads a JAR containing a Dex payload and uses IMSI checks to target victims; the report includes IOC details and screenshots of an unauthenticated C2 admin panel.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
