New Android Trojan 'SoumniBot' Evades Detection with Clever Tricks
ID: 5fa1c4ea-a8b7-5de4-8a18-86836cd13cbf
STIX ID: report--5fa1c4ea-a8b7-5de4-8a18-86836cd13cbf
Feed Name: The Hacker News
SoumniBot is a recently observed Android banking trojan targeting users in South Korea that exploits weaknesses in Android manifest parsing (invalid compression method, misreported archived size, and long XML namespaces) to obfuscate its behavior and hinder analysis; after installation it collects device metadata, contacts, SMS, photos, videos, installed apps and South Korean GPKI banking certificates, maintains persistence, can manipulate contacts/SMS and hide its icon, and communicates with hard-coded C2 servers over MQTT. Google reported no samples on the Play Store and Play Protect protects against known variants.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
