MalBus: Popular South Korean Bus App Series in Google Play Found Dropping Malware After 5 Years of Development

2019-02-04 Mcafee

https://www.mcafee.com/blogs/other-blogs/mcafee-labs/malbus-popular-south-korean-bus-app-series-in-google-play-found-dropping-malware-after-5-years-of-development/

McAfee reported that malicious Android code was delivered through a plugin masquerading as part of a long-running South Korean bus app series. The apps had been available through Google Play for years before removal, giving the attacker a trusted distribution context. The case highlights mobile supply-chain and plugin abuse risks where users install software tied to a familiar regional transportation service.

Indicators of Compromise

Type Value First Seen Last Seen
HASH b8b5d82eb25815dd3685630af9e9b09… 2019-02-04 2019-02-04
HASH ecb6603a8cd1354c9be236a3c3e7bf4… 2019-02-04 2019-02-04
HASH 20e6391cf3598a517467cfbc5d327a7… 2019-02-04 2019-02-04
HASH e71dc11e8609f6fd84b7af78486b05a… 2019-02-04 2019-02-04
HASH 12518eaa24d405debd014863112a3c0… 2019-02-04 2019-02-04
HASH 91f8c1f11227ee1d71f096fd97501c1… 2019-02-04 2019-02-04
HASH 3252fbcee2d1aff76a9f18b858231ad… 2019-02-04 2019-02-04
HASH 19162b063503105fdc1899f8f653b42… 2019-02-04 2019-02-04
HASH bed3e665d2b5fd53aab19b8a62035a5… 2019-02-04 2019-02-04
HASH b9d9b2e39247744723f72f63888deb1… 2019-02-04 2019-02-04
URL https://www.mcafeemobilesecurit… 2019-02-04 2019-02-04

Related Reports

« Back