216.73.216.6

The Mobile Malware Chronicles: Necro.N - Volume 101

· Published 21/10/2024 10:49 · Modified 21/10/2024 10:53

Export JSON

Essential information

Published
21/10/2024 10:49
Modified
21/10/2024 10:53
Tags
2024-10-21 advertising sdk c2 server fleeceware joker libcoral.so libsvm.so mobile malware necro.n obfuscation steganography
Related entities
6 observables, 2 malware

Description

Zimperium's zLabs researchers have been tracking , a highly intrusive campaign, since July. This malware, potentially succeeding , uses and to hide malicious payloads within images. It downloads payloads from C2 servers, enabling remote code execution on infected devices. The malware is distributed through a deceptive integrated into mobile apps. Two main libraries, '' and '', are used to execute the malicious code. Out of 37 samples analyzed, 78% used '' and 22% used ''. The malware can install applications, open invisible WebViews, and subscribe victims to unwanted paid services. Zimperium's on-device detection engine has successfully identified and neutralized all related malware samples and malicious URLs.

External references