APT41

Malware family · 5 sample(s) · 10 indicator record(s) · 3 signing certificate(s)

About APT41

Android surveillanceware (Lookout calls the two documented strains WyrmSpy and Dragonegg) attributed to the China-nexus actor APT41. Highly permission-hungry implants focused on call logs, SMS, contacts, audio capture and location tracking, masquerading as legitimate apps (e.g. fake security updates or romanticesque apps) and persist via a BootReceiver. The C2 server, password, version and a CustomId sit as meta-data in the manifest; additional http(s) C2 URLs hide as const-strings in a *Root class's DownRootPlan() method.

Indicators

IndicatorTypeSampleFirst seen
116.205.4.18:33889/control/ ip 1107200102a2… 2024-03-08
116.205.4.18:33889/control/ ip 391d22d89fc8… 2024-03-08
116.205.4.18:33889/control/ ip 48e3f32e770f… 2024-03-08
116.205.4.18:33889/control/ ip 4e5379745f10… 2024-03-08
116.205.4.18:33889/control/ ip b66847d571e4… 2019-09-15
121.42.149.52:8002/ ip 1107200102a2… 2024-03-08
121.42.149.52:8002/ ip 391d22d89fc8… 2024-03-08
121.42.149.52:8002/ ip 48e3f32e770f… 2024-03-08
121.42.149.52:8002/ ip 4e5379745f10… 2024-03-08
121.42.149.52:8002/ ip b66847d571e4… 2019-09-15