Super Mario Run Malware #2 – DroidJack RAT
ID: 7e9a5b81-4eb1-5ba8-bee1-9bcfb75a8755
STIX ID: report--7e9a5b81-4eb1-5ba8-bee1-9bcfb75a8755
Feed Name: Zscaler Security Research Blog
This Zscaler ThreatLabZ analysis describes a DroidJack (SandroRAT) Android RAT distributed as a fake Super Mario Run app; the malware records calls, captures video/photos, harvests SMS and WhatsApp data, persists information in local databases, and exfiltrates to a hardcoded command-and-control server. The report includes technical artifacts (code snippets and screenshots), demonstrates active device registration and data collection routines, and recommends installing apps only from trusted stores and disabling installation from unknown sources.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
