2025-10-02 (THURSDAY): ANDROID MALWARE

NOTES:

REFERENCES:

ASSOCIATED FILES:

 

NOTES:

 

IMAGES


Shown above:  Telegram channel where I downloaded the malware from.

 


Shown above:  Screenshot of the app icon in the device's home screen after I downloaded it.

 


Shown above:  Screenshot of the login screen that appears when you first open the app.

 


Shown above:  Screenshot of the app after I logged in.

 


Shown above:  I had the choice to change server locations.

 


Shown above:  Traffic from the Android device when I downloaded, opened, and logged into the malicious app.

 


Shown above:  TCP stream of configuration traffic after I'd logged into the malicious app.

 


Shown above:  TCP stream of websocket traffic generated by the app after logging in.

 

Click here to return to the main page.