Script-Bot Dropper (provisional)

Malware family · 1 sample(s) · 2 indicator record(s) · 1 signing certificate(s) · Active 2026-10-01 (experimental)

About Script-Bot Dropper (provisional)

Script-Bot Dropper (provisional, package com.mmtjb3) is a thin Android stub whose real logic is delivered as a hot-updated Lua/script bundle, so almost nothing malicious ships inside the APK itself. It polls an Alibaba Cloud OSS bucket (maomaotoujioben.oss-cn-hangzhou.aliyuncs.com) and a short-link resolver (dwz.junwfk.com) for its script payload and commands. Behaviour is click-fraud / automation botting driven entirely by the remotely served scripts.

Indicators

IndicatorTypeSampleFirst seen
dwz.junwfk.com/1JcMi domain 8bd23d6635f1… 2026-10-01
maomaotoujioben.oss-cn-hangzhou.aliyuncs.com/mmtjb3/version.txt domain 8bd23d6635f1… 2026-10-01