"SoumniBot: Evading Detection and Exploiting Android Weaknesses"

1 min read
Source: BleepingComputer
"SoumniBot: Evading Detection and Exploiting Android Weaknesses"
Photo: BleepingComputer
TL;DR Summary

A new Android banking malware called SoumniBot is evading detection by exploiting weaknesses in the Android manifest extraction and parsing procedure, allowing it to steal information from infected devices. The malware uses three different methods to manipulate the manifest file's compression and size, tricking Android's parser and evading security checks. SoumniBot targets Korean users, hides its icon after installation, and remains active in the background, uploading data from the victim. Kaspersky has informed Google about the evasion methods, and provides indicators of compromise for the malware.

Share this article

Reading Insights

Total Reads

0

Unique Readers

1

Time Saved

3 min

vs 3 min read

Condensed

85%

59186 words

Want the full story? Read the original article

Read on BleepingComputer