logo

Joker Joking in Google Play

ID: 8b293416-62ac-5904-95c5-ced5c3e9e31e

STIX ID: report--8b293416-62ac-5904-95c5-ced5c3e9e31e

Feed Name: Zscaler Security Research Blog

Threat Score
70/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

**Executive Summary:** This ThreatLabz analysis documents an active Joker Android malware campaign that repeatedly uploaded multiple malicious apps to Google Play (about 11 recent samples with ~30k installs), outlining targeted categories and publisher naming patterns, new evasion techniques (use of URL shorteners, changing C2 URIs, evolving string obfuscation), abuse of notification access to exfiltrate SMS/contacts and enroll victims in premium WAP services, staged payload innovations (XORed stage data, XXTEA-encrypted C2 communications, SIM-based targeting), and provides package names, IOCs and C2 hosts to aid detection and takedown.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.