
10/14/2023 · Blake Darché, Armen Boursalian, Javier Castro
What this post added
This post details the discovery and analysis of a malicious Android application impersonating the legitimate RedAlert - Rocket Alerts application. It describes the attack vector (domain impersonation, modified open-source code), the malicious APK's capabilities (data exfiltration of SIM info, contacts, SMS, accounts, call logs, installed apps), its encryption methods (AES-CBC, RSA), anti-analysis techniques (anti-debugging, anti-emulation, anti-test), and provides indicators of compromise (IOCs) including the malicious APK download URL, C2 IP address, APK hash, and public key.