Android Malware Posing as Google Play Store App Installer
ID: f2fcbb72-ad7e-5d7c-9ac6-627c436e6e7f
STIX ID: report--f2fcbb72-ad7e-5d7c-9ac6-627c436e6e7f
Feed Name: Cyble Blog
This Cyble report analyzes the Coper Android banking trojan (an ExoBotCompat/Exobot derivative), documenting its dropper-based multi-stage infection, packed native library that decrypts and loads malicious dex, extensive privileged permissions (device admin, accessibility, notification listener), capabilities to intercept SMS/notifications, keylog, run VNC screen capture, execute USSD/SMS commands, and persist via self-restoration; it includes hardcoded and dynamic C2 domains, IOC hashes/URLs, MITRE mappings, and detection/remediation guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
