Joker Playing Hide-and-Seek with Google Play
ID: 4ec9c822-1275-59df-a81c-34bc7e6c2f41
STIX ID: report--4ec9c822-1275-59df-a81c-34bc7e6c2f41
Feed Name: Zscaler Security Research Blog
Zscaler ThreatLabZ analyzed multiple Joker malware variants found on Google Play (17 samples, ~120,000 downloads) that use varied staging techniques (direct, one-stage, two-stage), string obfuscation (custom separators), AES/DES encryption, and remote C2-hosted payloads to deliver a final payload that steals SMS, contacts and enrolls victims in premium WAP services; the report provides MD5s, package names, payload distribution URLs, final C2 IPs, and recommendations to review app permissions and user reviews.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
