New Android Malware Targets Chinese Crypto Users
ID: 87f6aac2-11d8-5d01-b95a-b557fc8415e2
STIX ID: report--87f6aac2-11d8-5d01-b95a-b557fc8415e2
Feed Name: Cyble Blog
Threat Score
New Enchant Android malware is distributed via fake adult websites and leverages Android Accessibility Service to target Chinese cryptocurrency users, harvesting mnemonics, private keys, wallet passwords, addresses and asset details from specific wallet apps (imToken, OKX, Bitpie, TokenPocket); the report provides technical analysis, C2 URLs (https://bat.xnxnxx.top), sample hashes, MITRE ATT&CK mappings, IOCs and mitigation recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
