A threat actor group has evolved from IRC wars to deploying destructive Android malware. The malware includes scripts that wipe the modem and bootloader via dd commands in custom ROMs, and uses "L-Obfuscation" with dynamic getattr/eval in Python to evade detection.
Investigated a group evolving from IRC wars to destructive Android malware. Highlights: Scripts wiping modem / bootloader via dd in custom ROMs. "L-Obfuscation" using dynamic getattr / eval in Python. submitted by /u/datapeice [link] [comments]