SHA1 hash:
- 59bc8cd2996f071ad29d8b8cfa9089bbf6a6b241
Description
This is a trojan that is built into third-party WhatsApp messenger mods and camouflaged as Google library classes. The names of the malicious classes are as follows: com.google.android.app.contex and androidx.activity.app.androidx. While the host application is being used, the trojan sends requests to one of these C&C servers:
- https[:]//googapis[.]org
- https[:]//apisgoogle[.]org
In return, the trojan receives two URLs. One of them is intended for Russian-speaking users, and the other is for everyone else. Next, the trojan displays a dialog box with the content downloaded from the server. When the user clicks on the confirmation button, the corresponding link is loaded in the browser.