StealJob: New Android Malware Used by Donot APT Group
released on 2019-04-16 @ 06:37:10 PM
Donot (APT-C-35), named and tracked by PatchSky TIC, is an attack group that mainly targets countries such as Pakistan in South Asia.
This APT group usually carries out target attacks against government agencies to steal sensitive information. In addition to spreading malware via spear fishing email with Office attachment containing either vulnerability or malicious macro, this group is particularly good at leveraging malicious Android APKs in the target attacks.
Recently, we have observed a large-scale upgrade of its malicious Android APK framework to make it more stable and practical. Since the new APK framework is quite different from the one used in the past, we named it as StealJob since “job” is frequently used in the code.