RAZOR_TIGER__2019__First_Active_Attack_Exploiting_CVE-2019-2215_Found_on_Google_Play_Linked_to_SideWinder_APT_Group.pdf
ID: b5b7c479-52d0-4d9c-806e-e35a3c5814a1
STIX ID: report--b5b7c479-52d0-4d9c-806e-e35a3c5814a1
Threat Score
85/100
Uploaded: 2026-08-19
Published Date: 2020-01-06
Last Modified Date: 2020-01-06
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Trend Micro discovered three malicious Android apps on Google Play—disguised as photography and file-manager tools—that are linked to the SideWinder APT. The apps act as multi-stage droppers that fetch extra DEX code from C2 servers, exploit vulnerabilities (including CVE-2019-2215 and MediaTek-SU) to obtain root on select devices, enable Accessibility and unknown-source installs, deploy a hidden payload (callCam) that collects and encrypts sensitive data (accounts, messages, screenshots, device info), and exfiltrates it to attacker-controlled servers; the post includes technical code snippets, IOCs (hashes, package names, C2 domains) and a MITRE ATT&CK mapping.
