DocSwap Malware Masquerades as Security Document Viewer to Target Android Users Globally – Active IOCs

2025-03-19 Rewterz

https://rewterz.com/threat-advisory/docswap-malware-masquerades-as-security-document-viewer-to-target-android-users-globally-active-iocs

Thumbnail for DocSwap Malware Masquerades as Security Document Viewer to Target Android Users Globally – Active IOCs

The malware uses a custom protocol designed to mimic HTTPS traffic, adding another layer of stealth. Organizations should also educate users on social engineering tactics and implement strict security policies to prevent such malware infections. Once installed, the malware requests excessive permissions, including access to contacts, storage, and SMS, allowing it to exfiltrate sensitive data. Its core functionality relies on a native library that exfiltrates device information, contact lists, and SMS messages to a command-and-control (C2) server using an encrypted communication protocol.

Indicators of Compromise

Type Value First Seen Last Seen
HASH bf134495142d704f9009a7d325fb954… 2025-03-13 2025-03-19

Related Reports

« Back