[ << ALL_FEED ]

Citizen, update yourself 🫵

More in General

Citizen, update yourself 🫵

Recently, a sample mir-pay.apk flew into our sandbox. At first glance, nothing unusual: just another variation of the well-known Mamont malware, we thought. Especially since the name of this payment system has already appeared more than once in this malware family.

In the sandbox, the “Format tampered” label triggered with the verdict apk.tampered, the sample saved suspicious files with the .png extension (file drops) and loaded code directly into memory (DEX dumps).

We decided to dig deeper — and for good reason. During our research, we managed to:

• Determine that this sample has nothing to do with Mamont — a search using the discovered IoCs led us to the malicious campaign Falcon, whose first samples were described back in 2022.

• Reconstruct the entire attack chain — from the loader of a fake “app update” to a full-fledged Android backdoor — and understand how the threat actors use legitimate services, including Trello, to deliver malware.

• Compare samples from four years ago with current versions and find out how Falcon has evolved since then: new obfuscation techniques have appeared, functionality has expanded, and the methods of delivering the malicious payload have changed.

Read about how the Falcon malicious campaign is structured in the detailed analysis in our blog on Habr.

#avlab #sandbox #ti #android
@ptescalator

More from ti_author

More from ti_author

More in General