TF-MAL-apk.dragonegg
📛 Threat Title
Malware family: DragonEgg
Description
ThreatFox malware family `apk.dragonegg`. Printable name: DragonEgg. Aliases: LightSpy.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
apk.dragonegg
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.dragonegg
IOC database
- Type
- domain
- Value
apk.dragonegg- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-apk.dragonegg
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.dragonegg
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:apt.etda.or.th
Last change to this tool card: 13 October 2023 Download this tool card in JSON format All groups using tool DragonEgg
-
web:cybersecuritynews.com
A Chinese-based state-sponsored espionage group, APT41 targets Android devices through spyware wyrmspy and Dragon egg which masquerades as legit applications.
-
web:malpedia.caad.fkie.fraunhofer.de
Android variant of ios.LightSpy. 2023-10-02 ⋅ ThreatFabric ⋅ ThreatFabric LightSpy mAPT Mobile Payment System Attack DragonEgg WyrmSpy lightSpy 2023-07-19 ⋅ Lookout ⋅ Justin Albrecht, Kristina Balaam Lookout Attributes Advanced Android Surveillanceware to Chinese Espionage Group APT41 DragonEgg WyrmSpy
-
web:securityaffairs.com
According to the report, some versions of WyrmSpy used unique signing certificates that were later used also by the author of DragonEgg . Lookout also discovered a link between the C2 infrastructure hard-coded into the malware's source code and Chengdu 404.
-
web:www.bugsfighter.com
How DragonEgg malware infected your device DragonEgg malware , a sophisticated spyware-type threat linked to the Chinese state-backed cyber-espionage group APT41, primarily infiltrates Android devices by masquerading as seemingly harmless applications or trojanized legitimate software.
-
web:www.cybermaterial.com
DragonEgg , a spyware malware , infiltrates Android operating systems, leveraging multiple downloaded modules for surveillance activities. Its inception dates back to January 2021, marking its prolonged presence in the cyber threat landscape.
-
web:www.enigmasoftware.com
DragonEgg Mobile Malware According to security researchers, a Chinese state-sponsored espionage group identified as APT41, also known by other aliases such as Barium, Earth Baku, and Winnti, has been actively employing WyrmSpy and the DragonEgg spyware malware to target Android mobile devices.
-
web:www.lookout.com
What are WyrmSpy and DragonEgg surveillanceware? WyrmSpy and DragonEgg are two advanced Android surveillanceware that Lookout attributes to high-profile Chinese threat group APT41, also known as Double Dragon, BARIUM, and Winnti. While APT41 is mostly known for exploiting web-facing applications and infiltrating traditional endpoint devices, these malware are rare reported instances of the ...
-
web:www.pcrisk.com
DragonEgg malware overview DragonEgg is a piece of sophisticated malicious software. It arrives onto Android devices under the guise of harmless-looking applications or trojanized legitimate software. This malware aims to evade detection by relying on modules downloaded after infiltration, thus appearing less suspicious initially.
-
web:www.threatintelreport.com
Both Android malware strains come with extensive data collection and exfiltration capabilities activated on compromised Android devices after deploying secondary payloads. While WyrmSpy disguises itself as a default operating system app, DragonEgg is camouflaged as third-party keyboard or messaging apps, using these guises to evade detection.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.