logo

RAZOR_TIGER__2019__First_Active_Attack_Exploiting_CVE-2019-2215_Found_on_Google_Play_Linked_to_SideWinder_APT_Group.pdf

ID: b5b7c479-52d0-4d9c-806e-e35a3c5814a1

STIX ID: report--b5b7c479-52d0-4d9c-806e-e35a3c5814a1

Threat Score

85/100

Uploaded: 2026-08-19

Published Date: 2020-01-06

Last Modified Date: 2020-01-06

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Trend Micro discovered three malicious Android apps on Google Play—disguised as photography and file-manager tools—that are linked to the SideWinder APT. The apps act as multi-stage droppers that fetch extra DEX code from C2 servers, exploit vulnerabilities (including CVE-2019-2215 and MediaTek-SU) to obtain root on select devices, enable Accessibility and unknown-source installs, deploy a hidden payload (callCam) that collects and encrypts sensitive data (accounts, messages, screenshots, device info), and exfiltrates it to attacker-controlled servers; the post includes technical code snippets, IOCs (hashes, package names, C2 domains) and a MITRE ATT&CK mapping.