Malware, Threat Intelligence

Android malware Wonderland evolves with dropper apps targeting Uzbekistan

Male hand holding smart phone outside.

As reported by The Hacker News, threat actors are increasingly employing sophisticated methods to distribute Android malware, with a notable surge in attacks leveraging malicious dropper applications. These droppers, disguised as legitimate software, are designed to deliver potent payloads like the Wonderland SMS stealer, primarily targeting users in Uzbekistan.

The Wonderland malware, formerly known as WretchedCat, facilitates real-time command execution and SMS theft, masquerading as Google Play or common file types. The financially motivated TrickyWonders group utilizes Telegram for coordination and distributes the malware through fake Google Play pages, Facebook ads, and compromised Telegram accounts. Dropper families like MidnightDat and RoundRift conceal the encrypted payload. Once installed, Wonderland intercepts one-time passwords (OTPs) for financial fraud, exfiltrates contact lists, and can send SMS messages. Users must enable installations from unknown sources, often tricked by fake update screens. The malware's bidirectional command-and-control (C2) communication and obfuscated code make it difficult to detect and reverse engineer. The supporting infrastructure is dynamic, with rapidly changing domains to evade blacklisting.

The evolution of Android malware, exemplified by Wonderland and similar threats like Cellik, Frogblight, and NexusRoute, highlights a growing trend of sophisticated, financially driven attacks. These campaigns are becoming more accessible to less technical actors through malware-as-a-service models and one-click APK builders.

Source: The Hacker News

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds