Rise of Banking Trojan Dropper in Google Play
ID: c070b934-b1a7-57a8-8643-8c27d36b8590
STIX ID: report--c070b934-b1a7-57a8-8643-8c27d36b8590
Feed Name: Zscaler Security Research Blog
Threat Score
Zscaler ThreatLabz discovered the Xenomorph banking trojan hidden inside Google Play apps (notably “Todo:Day manager”), which downloads malicious payloads from GitHub/Firebase, escalates to device-admin to block uninstall, intercepts SMS/notifications, and uses overlays to steal banking credentials and MFA codes; the report includes IoCs (package names, MD5s) and C2 infrastructure (GitHub links, Telegram-hosted RC4-encoded C2, and gogoanalytics domains).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
