logo

MoqHao Android Malware Evolves with Auto-Execution Capability

ID: a70a7fc3-e15d-5eaf-99f1-eacf81fd4a3c

STIX ID: report--a70a7fc3-e15d-5eaf-99f1-eacf81fd4a3c

Feed Name: The Hacker News

Threat Score
75/100

Date Published: 2024-02-09

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

**Executive summary:** The report describes a new auto-executing Android malware variant dubbed MoqHao (aka Wroba/XLoader) distributed via smishing that automatically runs after install, requests risky permissions, and harvests device metadata, contacts, SMS, photos and more; it also covers Bigpanzi, a long-running campaign that infects Android-based smart TVs and set-top boxes to build a large botnet used for DDoS, proxying and illicit streaming, with evidence of substantial scale across multiple countries.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.