ChinaSMSStealer

Malware family · 3 sample(s) · 3 indicator record(s) · 0 signing certificate(s)

About ChinaSMSStealer

SMS-intercepting stealer exfiltrating over email rather than a network C2: the SMTP account and password sit as const-strings in the i()/j() accessors of Lcom/phone/stop/db/a;. Detected by a four-part manifest fingerprint (INTERNET, activity.MainActivity, receiver.SMSReceiver, service.SecondService).

Indicators

IndicatorTypeSampleFirst seen
[email protected]:a123456 email ca9fcd32fe77… 2019-09-28
[email protected]:e520123 email 4eb770e004f6… 2019-10-04
[email protected]:w1314521W email fe00cfa0f75e… 2019-09-25