MiningDropper Turns Android Apps Into Multi-Stage Malware Delivery Systems
ID: 92a75abc-bb66-5982-b164-1f00cfe07863
STIX ID: report--92a75abc-bb66-5982-b164-1f00cfe07863
Feed Name: The Cyber Express
Threat Score
Researchers at Cyble identified MiningDropper, a modular Android malware framework abused at scale via a trojanized Lumolight app; it uses XOR/AES obfuscation, dynamic DEX loading, anti-emulation checks and multi-stage payload delivery to deploy cryptocurrency miners, infostealers, banking trojans and RATs (e.g., BTMOB), with campaigns targeting India and multiple global regions and over 1,500 samples observed in a month.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
