[ << ALL_FEED ]

DragonDoll: a matryoshka in the world of Android spies

More in General

DragonDoll: a matryoshka in the world of Android spies 🪆

At the beginning of this spring, PT ESC specialists discovered a previously unknown APK file uploaded from Saudi Arabia. The sample itself contained many Defense Evasion techniques.

To complicate analysis, the following were used:

• 1 BadPack technique
• 2 stages of loading native libraries
• 1 LLVM-based obfuscation
• 6 checks for execution in a virtual environment
• and a countless number of MBA expressions

After long suffering stages of analysis, with the help of emulation, the laws of Boolean algebra, and several hundred lines of code, our specialists unpacked the new Android spy DragonDoll 📱

During the investigation, we stumbled upon a large-scale attack involving this malware, targeting Android users from more than 26 countries, including Russia.

The attackers used GitHub as a source for distributing and continuously updating DragonDoll. A link to this repository led to a network of fake Chrome “update” sites, the content of which adapted to the victim’s language.

A breakdown of what lay beneath the layer of obfuscation — in our blog ⬅️

#TI #Android #Malware
@ptescalator

More from ti_author

More from ti_author

More in General