Brokewell: New Android Trojan Targeting Germany Users
ID: 6178a3ab-2c68-521a-85cb-7966cf8c90a8
STIX ID: report--6178a3ab-2c68-521a-85cb-7966cf8c90a8
Feed Name: Cyble Blog
CRIL identified a new Android banking Trojan called Brokewell distributed via a fake Chrome update site; the report attributes development to a developer known as “Baron Samedit,” describes a Gitea-hosted loader that installs the payload without external storage permissions, details extensive capabilities (overlay attacks, keylogging, cookie theft, screen/audio recording, automated gestures and permission abuses via the Accessibility service), documents active C2 infrastructure and ports, provides multiple IOCs (hashes, domains, URLs), and warns that the malware—currently focused on Germany—appears poised to evolve and expand.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
