DawDropper Mobile Malware
Summary
The threat targets Android devices and has been observed to mostly fetch and execute banking Trojans including Ermac 2.0, Octo, Hydra and TeaBot. The developers of the threat will allow their clients to utilize DawDropper for a limited period, depending on the paid fee, and usually, payment is required every month. In turn, the cybercriminals have managed to sneak the threat onto the official Google Play Store under the guise of over a dozen weaponized applications. Some examples of applications spreading DawDropper include Call Recorder, Crypto Utils, Eagle photo editor, FixCleaner, Lucky Cleaner, Rooster VPN, Super Cleaner, Universal Saver Pro, Unicc QR Scanners, etc. The attackers behind the DawDropper campaign exploited a legitimate third-party cloud service named Firebase Realtime Database to establish the Command-and-Control server of the operation.