logo

Android Marcher: Continuously Evolving Mobile Malware

ID: 51661a53-5b42-563a-94b5-bab847e07807

STIX ID: report--51661a53-5b42-563a-94b5-bab847e07807

Feed Name: Zscaler Security Research Blog

Threat Score
75/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

Android Marcher is an active mobile banking/infostealer campaign that uses fake Google Play and firmware update overlays to coerce victims into submitting credit card details and bank credentials. Recent variants expanded targeting across multiple countries (including Germany, Australia, France, Turkey, the US, and the UK), added checks for many popular apps (Play Store, WhatsApp, Viber, Skype, Facebook, Instagram, Chrome, Twitter, Gmail, UC Browser, Line), implemented simple base64 obfuscation, moved C2 communications to SSL, requests device admin rights, and is delivered via fake app stores, porn sites posing as Chrome updates, and fake firmware updates (e.g., Firmware_Update.apk); defenders are advised to restrict Unknown Sources and use trusted app stores.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.