Android malware targeting South Korean mobile users
ID: 775fd6c1-811b-5753-9167-b23ab3b9c041
STIX ID: report--775fd6c1-811b-5753-9167-b23ab3b9c041
Feed Name: Zscaler Security Research Blog
Threat Score
A ThreatLabZ analysis describes a malicious Android application masquerading as AhnLab's V3 Mobile Plus that targets South Korean bank users: it requests device administrator privileges, hides its icon, runs background services to steal SMS messages and NPKI authentication certificates, and exfiltrates this data to a command-and-control server; the report includes technical indicators, screenshots, and removal/mitigation guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
