MalBus Actor Changed Market from Google Play to ONE Store
2020-04-09 • Mcafee •
McAfee found a new MalBus Android variant inserted into a South Korean education app distributed through ONE Store after earlier MalBus activity had used Google Play. The malicious versions loaded an encrypted native payload after a 10-hour delay to evade dynamic analysis, then used libmovie.so as a downloader that decoded URLs, dropped curl, fetched RC4-encrypted ELF payloads from compromised servers, decrypted them, and executed the Libfunc export. The loaded code selected a C2 server, generated a target device identifier, and acted as a spy agent awaiting attacker commands. Notable capabilities included local TCP 1111 communication with native code and SMS/MMS capture that could be enabled or disabled by command strings.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 9fc914545fbb99b7e0d4a5207f5a2b3… | 2020-04-09 | 2020-04-09 |
| HASH | 178dddf38ec232d540bd88320521d81… | 2020-04-09 | 2020-04-09 |
| HASH | f99212b70729942923fe26b996791cd… | 2020-04-09 | 2020-04-09 |
| HASH | 1613b35c73c6497730490d7712ac015… | 2020-04-09 | 2020-04-09 |
| HASH | c5bff68022ead6302f710f1ce1c3d56… | 2020-04-09 | 2020-04-09 |
| HASH | c410cacbb0be8f649f082148c91f4ce… | 2020-04-09 | 2020-04-09 |
| HASH | 63d10c9cd105c7b17effef18d31d571… | 2020-04-09 | 2020-04-09 |
| HASH | d328373cd67c467485b9c96349a0ee0… | 2020-04-09 | 2020-04-09 |
| HASH | df651ac1bfd60cd29cea85cc410002b… | 2020-04-09 | 2020-04-09 |
| HASH | 5e57bc8d83a372bf4d046c272cd43db… | 2020-04-09 | 2020-04-09 |