Discovered a GitHub repo hosting 20+ mParivahan-themed Android apps, including droppers using .enc payloads to build and deploy the final APK.
Github - weddingcard1910
@smica83@skocherhan@malwrhunterteam#Malware#ThreatIntel
@malwrhunterteam@skocherhan C2: https://ptnrmat[.]xyz/police/mydata.php
#Android#malware scans documents, images, WhatsApp media, contacts & device info, then uploads them to a remote C2
#ClickFix
1⃣ 📷 Caught a live #ClickFix lure: hxxps://vimcolors[.]com/ Looks like a routine Cloudflare "human check." It isn't. On load it copies a hidden PowerShell one-liner to your clipboard and social-engineers you into running it yourself. 📷 🧵
2⃣ The "verification steps" = Win+X → Terminal (I) → Ctrl+V → Enter. Clipboard payload
🔗Urlyze Report: https://t.co/OkZgse5pUt
@JoenOwek@malwrhunterteam@smica83@skocherhan Thanks for clarifying. I analyzed llst.ps1 and identified it as malicious.
e344f19dd0bd71e8c016d6848563122f96fc5dba426e176b3ba0a7a39aa1a321