logo

Android Marcher now marching via porn sites

ID: d3288886-7106-56df-9e57-8cbe1503a449

STIX ID: report--d3288886-7106-56df-9e57-8cbe1503a449

Feed Name: Zscaler Security Research Blog

Threat Score
70/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

This report analyzes a recent wave of the Android Marcher Trojan distributing AdobeFlashPlayer.apk via pornographic and other malicious sites; once installed (it requests device admin), Marcher reports installed packages to C2, displays fake Google Play payment screens and targeted banking overlays to steal financial credentials, and exfiltrates data to identified C2 URLs. The document provides technical details of the infection flow, affected banking apps, screenshots of behavior, and a list of IOCs for detection and mitigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.