Adult themed Android SMS Stealer Trojan
ID: 9bdb0423-b3d4-5ce4-bb3a-ec4f63056ca9
STIX ID: report--9bdb0423-b3d4-5ce4-bb3a-ec4f63056ca9
Feed Name: Zscaler Security Research Blog
The report analyzes an Android porn-themed malicious app (package ugo.jkh.efp, MD5 f71f8db8994699299b0bcda31d951c41) that lures users to install it, downloads a cj.jar and XML-hosted dropper APKs, and ultimately installs SMS-stealing and premium-SMS fraud apps that intercept and suppress messages, extract verification codes, and submit premium purchase requests—causing financial loss. The analysis includes indicators (URLs and APKs), technical behavior (broadcast receivers, pending intents, SMS interception), VirusTotal detection, and removal recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
