Wednesday, April 30, 2025
HomeAndroidNew Android Spyware As TV Streaming App Steals Sensitive Data From Devices

New Android Spyware As TV Streaming App Steals Sensitive Data From Devices

Published on

SIEM as a Service

Follow Us on Google News

Recent research has revealed a new Android malware targeting mnemonic keys, a crucial component for cryptocurrency wallet recovery.

Disguised as legitimate apps, this malware scans devices for images containing mnemonic phrases. Once installed, it covertly steals personal data like text messages, contacts, and images. 

The research has identified over 280 such malicious apps targeting Korean users since January 2024, where the malware uses deceptive tactics like loading screens and redirects to mask its data theft activities.

- Advertisement - Google News
Timeline of this campaign

Malicious actors primarily target Korean mobile users through sophisticated phishing campaigns. These campaigns employ deceptive tactics, such as impersonating trusted entities, to lure victims into clicking on malicious links.

Decoding Compliance: What CISOs Need to Know – Join Free Webinar

Once clicked, these links redirect users to counterfeit websites designed to mimic legitimate platforms by tricking users into downloading APK files, which are disguised as harmless applications. 

Upon installation, these malicious APKs request excessive permissions, enabling them to steal sensitive user data and execute nefarious activities in the background.

Fake Websites

The malware functions as a data exfiltration tool, stealing sensitive information from the user’s device and sending it to a remote server by targeting contacts, SMS messages, photos, and device information. 

It acts as a remote agent, receiving and executing commands from the server, which include acknowledging received data, modifying device settings, and sending SMS messages.

The investigation revealed a poorly secured command and control server that exposed sensitive data, including victim images and cryptocurrency wallet details, which allowed unauthorized access to index pages and admin panels, providing insights into the attacker’s operations. 

OCR details on Admin page

Python and Javascript were used to process stolen data, with OCR techniques employed to extract information from images demonstrating the attacker’s intent to exploit victim data for financial gain.

The malware has significantly evolved its communication and detection evasion strategies, which now utilize WebSocket connections for more efficient and real-time communication with its C2 server, making it harder to detect using traditional HTTP-based tools. 

It has also implemented advanced obfuscation techniques, such as string encoding and irrelevant code insertion, to confuse analysts and delay detection.

The malware has expanded its targeting to include the UK, demonstrating a deliberate attempt to broaden its reach and attack new user groups.

According to McAfee, the malware, initially disguised as loan or government apps, has evolved to exploit emotional vulnerabilities by mimicking obituary notices, where the perpetrators use OCR technology to analyze stolen data for financial gain. 

Despite its limited prevalence, the malware’s impact is amplified through deceptive SMS messages sent to victims’ contacts, and the team has reported active URLs to content providers for removal. 

The discovery of an “iPhone” item in the admin panel hints at a potential iOS variant, emphasizing the need for caution across all platforms.

Users should be wary of installing apps and granting permissions, storing important information securely, and using security software. 

Simulating Cyberattack Scenarios With All-in-One Cybersecurity Platform – Watch Free Webinar

Aman Mishra
Aman Mishra
Aman Mishra is a Security and privacy Reporter covering various data breach, cyber crime, malware, & vulnerability.

Latest articles

Trellix Launches Phishing Simulator to Help Organizations Detect and Prevent Attacks

Trellix, a leader in cybersecurity solutions, has unveiled its latest innovation, the Trellix Phishing...

AiTM Phishing Kits Bypass MFA by Hijacking Credentials and Session Tokens

Darktrace's Security Operations Center (SOC) in late 2024 and early 2025, cybercriminals have been...

Nitrogen Ransomware Uses Cobalt Strike and Log Wiping in Targeted Attacks on Organizations

Threat actors have leveraged the Nitrogen ransomware campaign to target organizations through deceptive malvertising...

Researchers Reveal Threat Actor TTP Patterns and DNS Abuse in Investment Scams

Cybersecurity researchers have uncovered the intricate tactics, techniques, and procedures (TTPs) employed by threat...

Resilience at Scale

Why Application Security is Non-Negotiable

The resilience of your digital infrastructure directly impacts your ability to scale. And yet, application security remains a critical weak link for most organizations.

Application Security is no longer just a defensive play—it’s the cornerstone of cyber resilience and sustainable growth. In this webinar, Karthik Krishnamoorthy (CTO of Indusface) and Phani Deepak Akella (VP of Marketing – Indusface), will share how AI-powered application security can help organizations build resilience by

Discussion points


Protecting at internet scale using AI and behavioral-based DDoS & bot mitigation.
Autonomously discovering external assets and remediating vulnerabilities within 72 hours, enabling secure, confident scaling.
Ensuring 100% application availability through platforms architected for failure resilience.
Eliminating silos with real-time correlation between attack surface and active threats for rapid, accurate mitigation

More like this

Trellix Launches Phishing Simulator to Help Organizations Detect and Prevent Attacks

Trellix, a leader in cybersecurity solutions, has unveiled its latest innovation, the Trellix Phishing...

AiTM Phishing Kits Bypass MFA by Hijacking Credentials and Session Tokens

Darktrace's Security Operations Center (SOC) in late 2024 and early 2025, cybercriminals have been...

Nitrogen Ransomware Uses Cobalt Strike and Log Wiping in Targeted Attacks on Organizations

Threat actors have leveraged the Nitrogen ransomware campaign to target organizations through deceptive malvertising...