Threats Tagged 'firebase c2'
View all threats tagged with 'firebase c2'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'firebase c2'
Click on any threat for detailed analysis and mitigation recommendations
A sophisticated mobile threat linked to Indonesian actors combines ransomware and spyware capabilities in a single attack vector. The malware is distributed via third-party file-sharing platforms through social engineering, targeting Android devices. It requests extensive permissions including device administrator, SMS, contacts, and accessibility access. The threat encrypts files using AES on Android 9 and earlier, appending .enc extensions, while stealing sensitive data including screen recordings, browser history, PINs, contacts, call logs, SMS messages, WhatsApp and Telegram chats. It establishes C2 communication via HTTPS and WebSockets using dynamic domain resolution through GitHub. Version 2 introduces UI hijacking, screen blocking, touch input interception, harassment features, and remote text-to-speech capabilities. The malware exfiltrates data through Firebase and Catbox services, enabling double-extortion through an interactive chat portal for ransom demands. Join the discussion | AlienVault OTX General | 09/09/2026, 20:59:12 UTC Added: 09/10/2026, 09:22:42 UTC |
An Android malware campaign masquerading as a bank KYC verification application targets users in India through WhatsApp distribution. The threat operates as a multi-stage dropper installing secondary payloads while establishing persistent command-and-control communication. It combines native code obfuscation, Firebase-based remote execution, VPN-based traffic manipulation, and WebView-based phishing to systematically harvest sensitive user data. The infection chain progresses through deceptive update screens, VPN activation, silent APK installation, and extensive permission abuse. The deployed payload enables SMS interception, call control, USSD execution, and structured credential theft through staged phishing interfaces mimicking legitimate banking workflows. Exfiltrated data is encrypted locally and transmitted to jsonapi.biz, while critical configuration values are hidden inside native libraries to hinder detection. Join the discussion | AlienVault OTX General | 04/29/2026, 09:43:48 UTC Added: 04/29/2026, 10:22:37 UTC |
Showing 1 to 2 of 2 results