logo

Fake Security App For AliPay Customers

ID: d6f33dc3-60e3-576f-8cf6-60bdfc91f89a

STIX ID: report--d6f33dc3-60e3-576f-8cf6-60bdfc91f89a

Feed Name: Zscaler Security Research Blog

Threat Score
65/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

This report analyzes an Android SMS‑stealing Trojan disguised as an AliPay “Security Controls” app (MD5: fad55b4432ed9eeb5d7426c55681586c, package com.bing.receive). The malware hides its icon, starts background services (MyService, DealService, TestService), registers broadcast receivers (including an SMS receiver and a system‑boot receiver), collects incoming SMS messages and forwards them via HTTP POST to a C2 server, and persists across reboots; the authors recommend uninstalling unknown apps, disabling unknown sources, and removing the app via Settings since it does not request device administrator privileges.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.