The popular app package “com.psiphon3” that known for providing uncensored access to Internet content was abused by attackers and they repack it with spyware framework.
Security researchers from Bitdefender found the new tainted version of the app that disseminates the malware.
“The original legitimate application is advertised as a privacy tool that enables access to the open internet when bundled with the
The tainted app was not distributed through Google Play, but it was through third-party app stores and the attackers bundled it with adware components(Google Ads, InMobi Ads, Mopub Ads) to generate revenue.
According to researchers, both the tampered and legitimate app has the same user interface and the attackers only embedded the
The new C&C server where the Triot dumping the information is still
“While the Triout Android spyware framework itself does not seem to have undergone changes in terms of code or capabilities, the fact that new samples are emerging and that threat actors are using extremely popular apps to bundled the malware,” researchers concluded.