Xenomorph
Malware family · 2 sample(s) · 5 indicator record(s) · 2 signing certificate(s)
About Xenomorph
Android banking trojan distributed as malware-as-a-service, famous for its heavy abuse of Android accessibility services to steal credentials from dozens of banking and crypto apps. C2 domains are RC4-encrypted (key + ":::" marker) inside the DEX.
Indicators
| Indicator | Type | Sample | First seen |
|---|---|---|---|
| datasciensonline.us | domain | 65c655663b9b… | 2022-07-28 |
| gogoanalytics.click | domain | 65c655663b9b… | 2022-07-28 |
| gogoanalytics.click | domain | ab345951a3e6… | 2022-08-09 |
| mybizzl.com | domain | 65c655663b9b… | 2022-07-28 |
| sallaka.com | domain | 65c655663b9b… | 2022-07-28 |