APT41
Malware family · 5 sample(s) · 10 indicator record(s) · 3 signing certificate(s)
About APT41
Android surveillanceware (Lookout calls the two documented strains WyrmSpy and Dragonegg) attributed to the China-nexus actor APT41. Highly permission-hungry implants focused on call logs, SMS, contacts, audio capture and location tracking, masquerading as legitimate apps (e.g. fake security updates or romanticesque apps) and persist via a BootReceiver. The C2 server, password, version and a CustomId sit as meta-data in the manifest; additional http(s) C2 URLs hide as const-strings in a *Root class's DownRootPlan() method.
Indicators
| Indicator | Type | Sample | First seen |
|---|---|---|---|
| 116.205.4.18:33889/control/ | ip | 1107200102a2… | 2024-03-08 |
| 116.205.4.18:33889/control/ | ip | 391d22d89fc8… | 2024-03-08 |
| 116.205.4.18:33889/control/ | ip | 48e3f32e770f… | 2024-03-08 |
| 116.205.4.18:33889/control/ | ip | 4e5379745f10… | 2024-03-08 |
| 116.205.4.18:33889/control/ | ip | b66847d571e4… | 2019-09-15 |
| 121.42.149.52:8002/ | ip | 1107200102a2… | 2024-03-08 |
| 121.42.149.52:8002/ | ip | 391d22d89fc8… | 2024-03-08 |
| 121.42.149.52:8002/ | ip | 48e3f32e770f… | 2024-03-08 |
| 121.42.149.52:8002/ | ip | 4e5379745f10… | 2024-03-08 |
| 121.42.149.52:8002/ | ip | b66847d571e4… | 2019-09-15 |