ChinaSMSStealer

Malware family · 3 sample(s) · 3 indicator record(s) · 0 signing certificate(s)

About ChinaSMSStealer

SMS-intercepting stealer exfiltrating over email rather than a network C2: the SMTP account and password sit as const-strings in the i()/j() accessors of Lcom/phone/stop/db/a;. Detected by a four-part manifest fingerprint (INTERNET, activity.MainActivity, receiver.SMSReceiver, service.SecondService).

Indicators

IndicatorTypeSampleFirst seen
17828583922@163.com:a123456 email ca9fcd32fe77… 2019-09-28
8376676115@qq.com:e520123 email 4eb770e004f6… 2019-10-04
angyongchaoa@aliyun.com:w1314521W email fe00cfa0f75e… 2019-09-25