SoumniBot Mobile Malware

General News

Summary

Understanding that threat hunters commonly initiate their analysis by examining the applications manifest file to ascertain its functionality, the malicious actors responsible for the malware have been observed utilizing three distinct techniques to complicate this process significantly. The SoumniBot Mobile Malware Takes Novel Measures to Avoid Detection The initial approach involves manipulating the Compression method value during the unpacking of the APKs manifest file using the libziparchive library. Despite being deemed invalid by unpackers with proper compression method validation, the Android APK parser correctly interprets such manifests, permitting the installation of the application. The final tactic involves employing lengthy XML namespace names within the manifest file, complicating the allocation of sufficient memory for analysis tools to process them. A notable attribute of SoumniBot is its capability to scan external storage media for .key and .der files containing paths leading to /NPKI/yessign, which corresponds to the digital signature certificate service provided by South Korea for governmental (GPKI), banking and online stock exchange (NPKI) purposes.

Classifications

industries
Entertainment
applications
Customer Service & Support

AskAI Classifications

Labels
Cybersecurity Software Anti-Malware Software SaaS Security

Linked Companies

EnigmaSoft
$1M to $5M