logo

Third-party Android App Store to SMS Trojan

ID: 39b5fc78-153d-50a7-93b1-d57d2dd2a2f5

STIX ID: report--39b5fc78-153d-50a7-93b1-d57d2dd2a2f5

Feed Name: Zscaler Security Research Blog

Threat Score
68/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

This report details an Android malware campaign distributed through a third‑party app store (“Smart Content Store”) where malicious APKs install invisible apps that request device administrator privileges, harvest device metadata and contacts, and send attacker‑controlled SMS messages (likely to premium or international numbers) causing potential financial harm; the writeup includes network indicators (e.g., app.in-spicy.com) and numerous sample MD5 hashes.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.