logo

Don't lose your privacy for Sarahah's Anonymity

ID: c65a97aa-82c4-5532-9548-cdf481e496c5

STIX ID: report--c65a97aa-82c4-5532-9548-cdf481e496c5

Feed Name: Zscaler Security Research Blog

Threat Score
75/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

The report details a DroidJack-built Android RAT distributed as a fake Sarahah app that requests device-admin privileges, hides itself, persists via a Controller service and boot receiver, and exfiltrates sensitive data (incoming and stored SMS, call recordings, contacts, GPS, camera/video, browser history) to an AES-encrypted C2; technical indicators include MD5 3a9c32d270f19384e148b0f24d916a5f and package name net.droidjack.server.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.