MasterFred Uses Gymdrop To Distribute Xenomorph Trojan
ID: 510a95f3-f3d0-5f12-84b9-283375b0450e
STIX ID: report--510a95f3-f3d0-5f12-84b9-283375b0450e
Feed Name: Cyble Blog
Threat Score
This report analyzes MasterFred, an Android hostile downloader disguised as a QR scanner that uses the Gymdrop dropper to download the Xenomorph banking trojan; it documents the infection chain (including Onion/C2 and download URLs), malicious capabilities (accessibility abuse to auto-enable permissions and device admin, SMS capture, HTML overlay phishing), attribution to Hadoken Security, and provides hashes and URLs as IOCs alongside mitigation recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
