New Android Malware Campaigns Evading Detection Using Cross-Platform Framework .NET MAUI

March 25, 2025, 7:20 p.m.

Description

Cybercriminals are exploiting .NET MAUI, a cross-platform development framework, to create Android malware that evades detection. These threats disguise themselves as legitimate apps, targeting users to steal sensitive information. The malware campaigns use techniques such as hiding code in blob files, multi-stage dynamic loading, and encrypted communications to avoid security measures. Two examples are discussed: a fake bank app targeting Indian users and a fake social media app targeting Chinese-speaking users. The latter employs advanced evasion techniques like excessive permissions in the AndroidManifest.xml file and encrypted socket communication. Users are advised to be cautious when downloading apps from unofficial sources and to use up-to-date security software for protection.

Date

  • Created: March 25, 2025, 6:56 p.m.
  • Published: March 25, 2025, 6:56 p.m.
  • Modified: March 25, 2025, 7:20 p.m.

Indicators

  • f70731d175739ae22e7b49cf9f0752dfa405d7f3ceae3a4b8a5c903185d0f2dc
  • eee469a0cf48f94e15d7f84c750cd820a46b6ae8211baed9023bcce446eac8e2
  • 510a87bb9636d7a71bcac6a2158d4fa6abbefbc115a0eadc9b1b43a10e9f14bb
  • 3c0d692f399aa40eac26c6e0754bf9612a46947a4adde51aef66a50ab3769ba3
  • 345eef06415790547537f434ba5a609e0eae805b282b3f9f916cc31b372c5dac
  • 0f5568d9ea1197e88b22d042d9d2b39c505ba062c63bf74b909cef8041c97086
  • 04b8902831ea4546d84146ba8dbf84656577656c43f41b09c5f6ce0b78ce16f6
  • e3e161277f820ab1277d25662f7e9da6ed36f7697881b8c6110682e9d043ac8f
  • 22f14ea4e540a695b97ce4518b6e5a6989565ce90c8601d38634ed5f865d851f
  • 16d176c09531da744093b90f223018370be10e8ad60edd74f84cbf16cb49e9b3
  • 157a896e9876f309241371e4470b5e32fa26c857aabf8c8ff89e71bd78b99263
  • 04139634480530a8565b4725b835b3c62684b8213c34f243b27ea6cee16861d9
  • 120.27.233.135

Additional Informations

  • Technology
  • Finance
  • British Indian Ocean Territory
  • India
  • China