MalBus Actor Changed Market from Google Play to ONE Store

2020-04-09 Mcafee

https://www.mcafee.com/blogs/other-blogs/mcafee-labs/malbus-actor-changed-market-from-google-play-to-one-store/

Thumbnail for MalBus Actor Changed Market from Google Play to ONE Store

McAfee found a new MalBus Android variant inserted into a South Korean education app distributed through ONE Store after earlier MalBus activity had used Google Play. The malicious versions loaded an encrypted native payload after a 10-hour delay to evade dynamic analysis, then used libmovie.so as a downloader that decoded URLs, dropped curl, fetched RC4-encrypted ELF payloads from compromised servers, decrypted them, and executed the Libfunc export. The loaded code selected a C2 server, generated a target device identifier, and acted as a spy agent awaiting attacker commands. Notable capabilities included local TCP 1111 communication with native code and SMS/MMS capture that could be enabled or disabled by command strings.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 9fc914545fbb99b7e0d4a5207f5a2b3… 2020-04-09 2020-04-09
HASH 178dddf38ec232d540bd88320521d81… 2020-04-09 2020-04-09
HASH f99212b70729942923fe26b996791cd… 2020-04-09 2020-04-09
HASH 1613b35c73c6497730490d7712ac015… 2020-04-09 2020-04-09
HASH c5bff68022ead6302f710f1ce1c3d56… 2020-04-09 2020-04-09
HASH c410cacbb0be8f649f082148c91f4ce… 2020-04-09 2020-04-09
HASH 63d10c9cd105c7b17effef18d31d571… 2020-04-09 2020-04-09
HASH d328373cd67c467485b9c96349a0ee0… 2020-04-09 2020-04-09
HASH df651ac1bfd60cd29cea85cc410002b… 2020-04-09 2020-04-09
HASH 5e57bc8d83a372bf4d046c272cd43db… 2020-04-09 2020-04-09

Related Reports

« Back