logo

New Android Trojan 'SoumniBot' Evades Detection with Clever Tricks

ID: 5fa1c4ea-a8b7-5de4-8a18-86836cd13cbf

STIX ID: report--5fa1c4ea-a8b7-5de4-8a18-86836cd13cbf

Feed Name: The Hacker News

Threat Score
75/100

Date Published: 2024-04-18

Date Updated: 2026-05-05

Author: [email protected] (The Hacker News)

...
...

SoumniBot is a recently observed Android banking trojan targeting users in South Korea that exploits weaknesses in Android manifest parsing (invalid compression method, misreported archived size, and long XML namespaces) to obfuscate its behavior and hinder analysis; after installation it collects device metadata, contacts, SMS, photos, videos, installed apps and South Korean GPKI banking certificates, maintains persistence, can manipulate contacts/SMS and hide its icon, and communicates with hard-coded C2 servers over MQTT. Google reported no samples on the Play Store and Play Protect protects against known variants.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.