Blog | G5 Cyber Security

Mobile spyware that steal Twitter credentials uses sandbox to Evade antivirus detections

Malware that uses a sandbox(Droid plugin) to dynamically load and run an app, without actually installing the app, just like VirtualApp. This makes it harder for antivirus solutions for recognizing the malware as its malicious parts are not put away in the host application. The malware masks itself as Wandoujia, a well known Android application store in China, and uses Droid plugin to install modules by utilizing Droid plugin. This malware has been recognized by Avast as Android:Agent-MOK.”]

Source: https://gbhackers.com/mobile-spyware-that-steal-twitter-credentials-uses-sandbox-to-evade-antivirus-detections/

Exit mobile version