logo

Android Malware Posing as Google Play Store App Installer

ID: f2fcbb72-ad7e-5d7c-9ac6-627c436e6e7f

STIX ID: report--f2fcbb72-ad7e-5d7c-9ac6-627c436e6e7f

Feed Name: Cyble Blog

Threat Score
72/100

Date Published: 2025-05-20

Date Updated: 2026-07-16

...
...

This Cyble report analyzes the Coper Android banking trojan (an ExoBotCompat/Exobot derivative), documenting its dropper-based multi-stage infection, packed native library that decrypts and loads malicious dex, extensive privileged permissions (device admin, accessibility, notification listener), capabilities to intercept SMS/notifications, keylog, run VNC screen capture, execute USSD/SMS commands, and persist via self-restoration; it includes hardcoded and dynamic C2 domains, IOC hashes/URLs, MITRE mappings, and detection/remediation guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.