PULSE NAME
KYCShadow: An Android Banking Malware Exploiting Fake KYC Workflows for Credential and OTP Theft
WHITE AlienVault 2026-04-29 Modified: 2026-04-29
9
IOCs
LOW VOLUME
An Android malware campaign masquerading as a bank KYC verification application targets users in India through WhatsApp distribution. The threat operates as a multi-stage dropper installing secondary payloads while establishing persistent command-and-control communication. It combines native code obfuscation, Firebase-based remote execution, VPN-based traffic manipulation, and WebView-based phishing to systematically harvest sensitive user data. The infection chain progresses through deceptive update screens, VPN activation, silent APK installation, and extensive permission abuse. The deployed payload enables SMS interception, call control, USSD execution, and structured credential theft through staged phishing interfaces mimicking legitimate banking workflows. Exfiltrated data is encrypted locally and transmitted to jsonapi.biz, while critical configuration values are hidden inside native libraries to hinder detection.
MITRE ATT&CK & Malware Families
MALWARE FAMILIES
KYCShadow
Indicators of Compromise (9)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 URL domain
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 3da35272ad6d280d3388d57bdbf61b9c 2026-04-29
FileHash-SHA1 0a467a2c936734affc8d796a4e468543b9d182e7 2026-04-29
FileHash-SHA256 1d261b45e73b5b712becb12ed182ec89d3dd0d73143a2dd8ff5512da489a50eb 2026-04-29
FileHash-SHA256 34479b18597f1a0deb5d55b8450bc21af1d1f638c4ceca1ee19e6f5ac89d6be2 2026-04-29
URL https://jsonapi.biz 2026-04-29
FileHash-SHA1 10bd31f7d0e47f8c24f58cac962036d342d57057 2026-04-29
domain jsonapi.biz 2026-04-29
domain jsonserv.biz 2026-04-29
domain jsonserv.xyz 2026-04-29