logo

Android apps infected with Windows malware reemerge

ID: a490d5f7-d3e8-5377-bf2b-806659d27eb6

STIX ID: report--a490d5f7-d3e8-5377-bf2b-806659d27eb6

Feed Name: Zscaler Security Research Blog

Threat Score
45/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

Researchers discovered around 150 Google Play APKs from multiple developers containing HTML files infected by the Ramnit worm which injects malicious iFrames; the malicious domains have been sinkholed so Android users were not impacted, but the infections indicate compromised developer systems or build environments and include MD5s and package names as IOCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.