GHOSTGRAB ANDROID MALWARE
Oct. 29, 2025, 6:27 p.m.
Description
GhostGrab is a sophisticated Android malware that combines cryptocurrency mining with extensive data theft. It exploits device resources for mining while harvesting sensitive information, including banking credentials, debit card details, and OTPs. The malware uses advanced persistence techniques, hiding its presence and resisting removal. It abuses permissions to access SMS, calls, and storage, enabling comprehensive data exfiltration. GhostGrab employs Firebase for command-and-control operations and data exfiltration, concealing malicious activity within legitimate cloud traffic. The malware's modular design and use of WebView-based phishing pages demonstrate its focus on financial fraud and identity theft. Its infrastructure includes recently registered domains and obfuscation services, indicating a professionally managed operation. This threat exemplifies the convergence of financial cybercrime and resource exploitation in mobile malware, highlighting the need for enhanced Android security measures.
Tags
Date
- Created: Oct. 29, 2025, 10:49 a.m.
- Published: Oct. 29, 2025, 10:49 a.m.
- Modified: Oct. 29, 2025, 6:27 p.m.
Indicators
- eae2c1f80b6d57285952b6e3da558d4c588a9972ee45ebd31c725772fe15edb3
- 29c60e17d43f7268431929836c1b72df60d3b7643ed177f858a9d9bbab207783
- http://pool.uasecurity.org:9000
- pool.uasecurity.org
- pool-proxy.uasecurity.org
- access.uasecurity.org
- api.uasecurity.org
- kychelp.live
- category.info
Additional Informations
- Finance