s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-apk.dragonegg

📛 Threat Title

Malware family: DragonEgg

Category: DragonEgg First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `apk.dragonegg`. Printable name: DragonEgg. Aliases: LightSpy.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain apk.dragonegg VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.dragonegg

IOC database

Type
domain
Value
apk.dragonegg
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-apk.dragonegg

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.dragonegg

References (1)

Remediations (10)

  • web:apt.etda.or.th

    Last change to this tool card: 13 October 2023 Download this tool card in JSON format All groups using tool DragonEgg

  • web:cybersecuritynews.com

    A Chinese-based state-sponsored espionage group, APT41 targets Android devices through spyware wyrmspy and Dragon egg which masquerades as legit applications.

  • web:malpedia.caad.fkie.fraunhofer.de

    Android variant of ios.LightSpy. 2023-10-02 ⋅ ThreatFabric ⋅ ThreatFabric LightSpy mAPT Mobile Payment System Attack DragonEgg WyrmSpy lightSpy 2023-07-19 ⋅ Lookout ⋅ Justin Albrecht, Kristina Balaam Lookout Attributes Advanced Android Surveillanceware to Chinese Espionage Group APT41 DragonEgg WyrmSpy

  • web:securityaffairs.com

    According to the report, some versions of WyrmSpy used unique signing certificates that were later used also by the author of DragonEgg . Lookout also discovered a link between the C2 infrastructure hard-coded into the malware's source code and Chengdu 404.

  • web:www.bugsfighter.com

    How DragonEgg malware infected your device DragonEgg malware , a sophisticated spyware-type threat linked to the Chinese state-backed cyber-espionage group APT41, primarily infiltrates Android devices by masquerading as seemingly harmless applications or trojanized legitimate software.

  • web:www.cybermaterial.com

    DragonEgg , a spyware malware , infiltrates Android operating systems, leveraging multiple downloaded modules for surveillance activities. Its inception dates back to January 2021, marking its prolonged presence in the cyber threat landscape.

  • web:www.enigmasoftware.com

    DragonEgg Mobile Malware According to security researchers, a Chinese state-sponsored espionage group identified as APT41, also known by other aliases such as Barium, Earth Baku, and Winnti, has been actively employing WyrmSpy and the DragonEgg spyware malware to target Android mobile devices.

  • web:www.lookout.com

    What are WyrmSpy and DragonEgg surveillanceware? WyrmSpy and DragonEgg are two advanced Android surveillanceware that Lookout attributes to high-profile Chinese threat group APT41, also known as Double Dragon, BARIUM, and Winnti. While APT41 is mostly known for exploiting web-facing applications and infiltrating traditional endpoint devices, these malware are rare reported instances of the ...

  • web:www.pcrisk.com

    DragonEgg malware overview DragonEgg is a piece of sophisticated malicious software. It arrives onto Android devices under the guise of harmless-looking applications or trojanized legitimate software. This malware aims to evade detection by relying on modules downloaded after infiltration, thus appearing less suspicious initially.

  • web:www.threatintelreport.com

    Both Android malware strains come with extensive data collection and exfiltration capabilities activated on compromised Android devices after deploying secondary payloads. While WyrmSpy disguises itself as a default operating system app, DragonEgg is camouflaged as third-party keyboard or messaging apps, using these guises to evade detection.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.