The Joker Trojan plays the Google PlayStore
released on 2020-06-10 @ 08:22:50 PM
APK Lab recently disclosed that two available apps that contain the Joker Trojan managed to sneak past protection systems and were uploaded to the Google Play Store. The apps containing the Trojan, called 'Speed Message' and 'Botmatic Messages', currently have over 11,000 installs combined. Further investigation into the IP address of the attacker’s C2 server led me to find three more apps, called 'Playful Game Station', 'Watch SMS', and 'HS Photo Collage', that all contain Joker Dropper too.