TF-MAL-apk.abstract_emu
📛 Threat Title
Malware family: AbstractEmu
Description
ThreatFox malware family `apk.abstract_emu`. Printable name: AbstractEmu.
Indicators of Compromise (0)
No indicators of compromise on this threat.
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:attack.mitre.org
AbstractEmu is mobile malware that was first seen in Google Play and other third-party stores in October 2021. It was discovered in 19 Android applications, of which at least 7 abused known Android exploits for obtaining root permissions.
-
web:github.com
Malicious traffic detection system. Contribute to stamparm/maltrail development by creating an account on GitHub.
-
web:hothardware.com
AbstractEmu gets on a device by pretending to be a legitimate piece of software. Lookout found nineteen apps that were front-ends for the malware , including one app—"Lite Launcher"—with over ...
-
web:malpedia.caad.fkie.fraunhofer.de
According to PCrisk, AbstractEmu is the name of rooting malware that can gain privileged access to the Android operating system. Threat actors behind AbstractEmu are using legitimate-looking apps (like password managers, app launchers, data savers) to trick users into downloading and opening/executing this malware .
-
web:threatfox.abuse.ch
A malware sample can be associated with only one malware family . The page below gives you an overview on indicators of compromise associated with apk. abstract_emu .
-
web:www.broadcom.com
AbstractEmu is an Android malware with spying and remote access capabilities, as well as the ability to gain root access. In late October, multiple instances were observed on both the Google Play Store and third-party stores.
-
web:www.bugsfighter.com
Detailed guide to remove AbstractEmu virus from Android. Download removal tool or use manual instructions in this article.
-
web:www.csoonline.com
The AbstractEmu lure applications that are distributed on app stores contain code that attempts to determine if the app is being run in an emulated environment or on a real device.
-
web:www.lookout.com
Background and Discovery Timeline Researchers in the Lookout Threat Lab have discovered 19 applications, some with as many as 10,000 downloads, present in mobile app stores. The malware , dubbed AbstractEmu , uses code abstraction and anti-emulation checks to avoid running while under analysis. This helps minimize the chance that it will be uncovered.
-
web:www.pcrisk.com
What kind of malware is AbstractEmu ? AbstractEmu is the name of rooting malware that can gain privileged access to the Android operating system. Threat actors behind AbstractEmu are using legitimate-looking apps (like password managers, app launchers, data savers) to trick users into downloading and opening/executing this malware .
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.