
SonicWall Threats Research team received yet another report about an Android malware hosted on Discord. The URL associated with this threat being -
The application requests for a number of suspicious permissions, some of them include:
The instance of malware that we analyzed masquerades itself as a legitimate McAfee application. Upon installation, the application is visible as below:
Once the app is executed, it requests for Accessibility service. If this service is granted, the malware does a number of things in the background as visible in the GIF below:
User device related information is sent to the attacker. This acts as an identifier for the infected device, the name of the PHP page further solidifies this:
The malware is capable of accepting a number of commands from the attacker, some of them are as listed below:
Overall this malware contains the capability to do a number of things once it infects a device. The power of Accessibility Services is on display as the malware grants a number of permissions and performs a multitude of actions once the user grants this permission.
Sonicwall Capture Labs provides protection against this threat using the signature listed below:
Indicators of Compromise:
Share This Article

An Article By
An Article By
Security News
Security News