logo

MasterFred Uses Gymdrop To Distribute Xenomorph Trojan

ID: 510a95f3-f3d0-5f12-84b9-283375b0450e

STIX ID: report--510a95f3-f3d0-5f12-84b9-283375b0450e

Feed Name: Cyble Blog

Threat Score
70/100

Date Published: 2025-11-18

Date Updated: 2026-07-16

...
...

This report analyzes MasterFred, an Android hostile downloader disguised as a QR scanner that uses the Gymdrop dropper to download the Xenomorph banking trojan; it documents the infection chain (including Onion/C2 and download URLs), malicious capabilities (accessibility abuse to auto-enable permissions and device admin, SMS capture, HTML overlay phishing), attribution to Hadoken Security, and provides hashes and URLs as IOCs alongside mitigation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.