Citizen, update yourself 🫵

More in General
- Operation Chewbacca
At the end of June, the PT ESC team, during incident investigations, discovered a new group…
- Ding, ding — who's there?
Ding, ding — who's there? 🔔 The cyber intelligence group of Positive Technologies' expert security center…
- Enterprise-grade validation system with schema support
Enterprise-grade validation system with schema support (c) The author of a dozen trojans who forgot to…
- One less feathered thief — plus one hundred rating points!
One less feathered thief — plus one hundred rating points! 😵 The Threat Intelligence team at…
- DragonDoll: a matryoshka in the world of Android spies
DragonDoll: a matryoshka in the world of Android spies 🪆 At the beginning of this spring,…
Citizen, update yourself 🫵
Recently, a sample mir-pay.apk flew into our sandbox. At first glance, nothing unusual: just another variation of the well-known Mamont malware, we thought. Especially since the name of this payment system has already appeared more than once in this malware family.
In the sandbox, the “Format tampered” label triggered with the verdict apk.tampered, the sample saved suspicious files with the .png extension (file drops) and loaded code directly into memory (DEX dumps).
We decided to dig deeper — and for good reason. During our research, we managed to:
• Determine that this sample has nothing to do with Mamont — a search using the discovered IoCs led us to the malicious campaign Falcon, whose first samples were described back in 2022.
• Reconstruct the entire attack chain — from the loader of a fake “app update” to a full-fledged Android backdoor — and understand how the threat actors use legitimate services, including Trello, to deliver malware.
• Compare samples from four years ago with current versions and find out how Falcon has evolved since then: new obfuscation techniques have appeared, functionality has expanded, and the methods of delivering the malicious payload have changed.
Read about how the Falcon malicious campaign is structured in the detailed analysis in our blog on Habr.
#avlab #sandbox #ti #android
@ptescalator
More in General
- Operation Chewbacca
At the end of June, the PT ESC team, during incident investigations, discovered a new group…
- Ding, ding — who's there?
Ding, ding — who's there? 🔔 The cyber intelligence group of Positive Technologies' expert security center…
- Enterprise-grade validation system with schema support
Enterprise-grade validation system with schema support (c) The author of a dozen trojans who forgot to…
- One less feathered thief — plus one hundred rating points!
One less feathered thief — plus one hundred rating points! 😵 The Threat Intelligence team at…
- DragonDoll: a matryoshka in the world of Android spies
DragonDoll: a matryoshka in the world of Android spies 🪆 At the beginning of this spring,…



