Android Marcher: Continuously Evolving Mobile Malware
ID: 51661a53-5b42-563a-94b5-bab847e07807
STIX ID: report--51661a53-5b42-563a-94b5-bab847e07807
Feed Name: Zscaler Security Research Blog
Android Marcher is an active mobile banking/infostealer campaign that uses fake Google Play and firmware update overlays to coerce victims into submitting credit card details and bank credentials. Recent variants expanded targeting across multiple countries (including Germany, Australia, France, Turkey, the US, and the UK), added checks for many popular apps (Play Store, WhatsApp, Viber, Skype, Facebook, Instagram, Chrome, Twitter, Gmail, UC Browser, Line), implemented simple base64 obfuscation, moved C2 communications to SSL, requests device admin rights, and is delivered via fake app stores, porn sites posing as Chrome updates, and fake firmware updates (e.g., Firmware_Update.apk); defenders are advised to restrict Unknown Sources and use trusted app stores.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
