lazarusholic

Everyday is lazarus.dayβ

RambleOn Android Malware

2022-12-30, InterLab
https://interlab.or.kr/archives/2567
#Mobile #Kimsuky #RambleOn

Contents

30 Dec Cyber Threat Report: RambleOn Android Malware
Detailed analysis report of cyber threat targeting journalist in South Korea through APT phishing campaign with malicious APK
Author : Ovi Liber, Threat Researcher @ Interlab
Publishing Date : 2022/12/30
Executive Summary
-
- A Journalist in South Korea recently received malicious APK file suggested to be installed on the journalist’s phone, suggested by anonymous tipper.
-
- Through analysis done by Interlab’s Threat Researcher Ovi Liber, it is found that the APK file and its behavior after installation contains critically malicious functionalities : including ability to read and leak target’s contact list, SMS, voice call content, location and others from the time of compromisation on the target.
-
- The malware named as RambleOn in this report, contains unique characteristic of 1) using infrastructure of pCloud and Yandex, 2) usage of FCM service for C&C communication.
Introduction
Freedom of media and journalism is essential to enable democratic, free, and participative societies. However, as …