New Android Malware Campaigns Evading Detection Using Cross-Platform Framework .NET MAUI
March 25, 2025, 7:20 p.m.
Description
Cybercriminals are exploiting .NET MAUI, a cross-platform development framework, to create Android malware that evades detection. These threats disguise themselves as legitimate apps, targeting users to steal sensitive information. The malware campaigns use techniques such as hiding code in blob files, multi-stage dynamic loading, and encrypted communications to avoid security measures. Two examples are discussed: a fake bank app targeting Indian users and a fake social media app targeting Chinese-speaking users. The latter employs advanced evasion techniques like excessive permissions in the AndroidManifest.xml file and encrypted socket communication. Users are advised to be cautious when downloading apps from unofficial sources and to use up-to-date security software for protection.
Tags
Date
- Created: March 25, 2025, 6:56 p.m.
- Published: March 25, 2025, 6:56 p.m.
- Modified: March 25, 2025, 7:20 p.m.
Indicators
- f70731d175739ae22e7b49cf9f0752dfa405d7f3ceae3a4b8a5c903185d0f2dc
- eee469a0cf48f94e15d7f84c750cd820a46b6ae8211baed9023bcce446eac8e2
- 510a87bb9636d7a71bcac6a2158d4fa6abbefbc115a0eadc9b1b43a10e9f14bb
- 3c0d692f399aa40eac26c6e0754bf9612a46947a4adde51aef66a50ab3769ba3
- 345eef06415790547537f434ba5a609e0eae805b282b3f9f916cc31b372c5dac
- 0f5568d9ea1197e88b22d042d9d2b39c505ba062c63bf74b909cef8041c97086
- 04b8902831ea4546d84146ba8dbf84656577656c43f41b09c5f6ce0b78ce16f6
- e3e161277f820ab1277d25662f7e9da6ed36f7697881b8c6110682e9d043ac8f
- 22f14ea4e540a695b97ce4518b6e5a6989565ce90c8601d38634ed5f865d851f
- 16d176c09531da744093b90f223018370be10e8ad60edd74f84cbf16cb49e9b3
- 157a896e9876f309241371e4470b5e32fa26c857aabf8c8ff89e71bd78b99263
- 04139634480530a8565b4725b835b3c62684b8213c34f243b27ea6cee16861d9
- 120.27.233.135
Additional Informations
- Technology
- Finance
- British Indian Ocean Territory
- India
- China