[jpshare]Security Experts from Avast came through a Malware that uses a sandbox(DroidPlugin) to dynamically load and run an app, without actually installing the app, just like VirtualApp.
This makes it harder for antivirus solutions for recognizing the malware, as its malicious parts are not put away in the host application.
This malware is spread through Evergreen social Engineering tactics and they are to steal user’s Twitter credentials.Avast said The malware masks itself as Wandoujia, a well known Android application store in China.
Interestingly, the malware developer presented an issue to DroidPlugin to report an out-of-memory issue around the time the new variation was discharged.
It hides all of its files within the asset directory, for DroidPlugin to run.It consists of many plugins and they do their functions.
Once of the plugin communicates with the C&C server and from that instructions will accomplish to other APK files.
The malware won’t really installed on the infected phone, rather it installs the modules by utilizing DroidPlugin.
Avast said “Based on our experience, we suspect this is done to bypass antivirus detections. If the host app doesn’t include malicious actions, and all the malicious actions are moved to plugins which are dynamically downloaded, it makes it difficult for antivirus solutions to detect the host app”.
While it can be easy to utilize a sandbox to run an application without installing it, sandboxes can likewise be utilized maliciously by malware developers.This malware has been recognized by Avast as Android:Agent-MOK
Sha-1 hash : e2b05c8fdf3b82660f7ab378e14b8feab81417f0Also Read:
AT&T and Verizon Communications, two of America's largest telecommunications providers, have confirmed they were targeted…
Researchers observed Lumma Stealer activity across multiple online samples, including PowerShell scripts and a disguised…
Palo Alto Networks reported the Contagious Interview campaign in November 2023, a financially motivated attack…
The recent discovery of the NjRat 2.3D Professional Edition on GitHub has raised alarms in…
A critical vulnerability, CVE-2024-3393, has been identified in the DNS Security feature of Palo Alto…
Threat Analysts have reported alarming findings about the "Araneida Scanner," a malicious tool allegedly based…