logo

Super Mario Run Malware #2 – DroidJack RAT

ID: 7e9a5b81-4eb1-5ba8-bee1-9bcfb75a8755

STIX ID: report--7e9a5b81-4eb1-5ba8-bee1-9bcfb75a8755

Feed Name: Zscaler Security Research Blog

Threat Score
70/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

This Zscaler ThreatLabZ analysis describes a DroidJack (SandroRAT) Android RAT distributed as a fake Super Mario Run app; the malware records calls, captures video/photos, harvests SMS and WhatsApp data, persists information in local databases, and exfiltrates to a hardcoded command-and-control server. The report includes technical artifacts (code snippets and screenshots), demonstrates active device registration and data collection routines, and recommends installing apps only from trusted stores and disabling installation from unknown sources.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.