
SonicWall Threats Research team identified a version of AndroSpy in the wild. Interestingly, there exists a Github repository for this version of the malware. This repository was created a few months back and appears to be fairly active.
This app requests a number of dangerous permissions, few of them are listed below:
This version of AndroSpy boasts a number of functionalities, some of them are listed below:
Searching for this app on Virustotal showed a number of related apps, some with different names and icons:
This indicates that this threat is being used and propagated with malicious intent. As mentioned earlier, the attacker server ad other configurations can be viewed under resources>res>values>strings
The github repository shows a BTC wallet address for donations towards this project:
Overall this is a spyware that is available on Github as a framework. This spyware is being used as legitimate application in some cases.
Sonicwall Capture Labs provides protection against this threat using the signature listed below:
Indicators of Compromise:
Share This Article

An Article By
An Article By
Security News
Security News