Android apps targeting JIO users in India
ID: a9d5f1a8-fff0-5810-b5a9-59c854c11848
STIX ID: report--a9d5f1a8-fff0-5810-b5a9-59c854c11848
Feed Name: Zscaler Security Research Blog
This Zscaler ThreatLabZ report details an Android malware campaign active since 2020 that leverages topical India-related social engineering (e.g., TikTok return, free Lenovo laptop) to trick users into installing malicious APKs hosted on attacker-controlled GitHub/Weebly pages. The malware requests permissions, prompts victims to share the app via WhatsApp, targets Jio subscribers by identifying contacts and SIMs, sends SMS to spread, displays ads for monetization, and includes reused cryptographic keys and multiple SDKs; the report provides technical analysis, TTPs and extensive IOCs (MD5s, package names, distribution URLs, GitHub handles).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
