216.73.217.98

'Evil Twin' Apps Spread for Multiple Fraud Schemes

· Published 17/07/2024 10:52 · Modified 17/07/2024 12:29

Export JSON

Essential information

Published
17/07/2024 10:52
Modified
17/07/2024 12:29
Tags
2024-07-17 ad fraud impersonation konfety malvertising mobile obfuscation
Related entities
1 malware

Description

HUMAN's Satori Threat Intelligence and Research team recently uncovered a massive operation dubbed , involving threat actors operating 'evil twin' versions of 'decoy twin' apps available on major app marketplaces. The decoy twins on official stores behave normally, while the evil twins conduct , install browser extensions, monitor web searches, and sideload malicious code onto devices by abusing an ad SDK called CaramelAds. This novel method represents fraudulent traffic as legitimate.

External references