logo

New Sneaky Xamalicious Android Malware Hits Over 327,000 Devices

ID: 41b2fc98-0330-5c0e-a661-72f0cc65581a

STIX ID: report--41b2fc98-0330-5c0e-a661-72f0cc65581a

Feed Name: The Hacker News

Threat Score
75/100

Date Published: 2023-12-27

Date Updated: 2026-04-23

Author: [email protected] (The Hacker News)

...
...

McAfee researchers identified an Android backdoor named Xamalicious, built with the Xamarin framework and abusing Android accessibility permissions to perform ad-fraud, app installs, click automation and to fetch a second-stage assembly DLL for full device control; 25 malicious apps (some previously on Google Play) are linked to the family with an estimated 327,000 installs across multiple countries. The report also describes a concurrent phishing campaign targeting Indian banking users via WhatsApp-distributed fake APKs that request SMS permissions and harvest banking credentials, cards, national ID data and intercepted SMS messages for unauthorized transactions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.