logo

Infostealer APK Posing As Microsoft Word Document

ID: 23c9d7f2-8970-5238-9eed-26ab4e058a2d

STIX ID: report--23c9d7f2-8970-5238-9eed-26ab4e058a2d

Feed Name: Zscaler Security Research Blog

Threat Score
70/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

*Analysis of an Android trojan disguised as a Microsoft Word file ('资料') that gains device administrator rights, collects IMEI/SIM/Device IDs, SMS messages and contact lists, exfiltrates them via hard-coded SMTP credentials, sends SMS to attacker-controlled numbers, and can execute calls; the campaign was active around October 10, 2015 with over 300 confirmed victims.*

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.