Researchers reported that Trojan-Dropper.AndroidOS.Shopper.a used Android's AccessibilityService to take over device interactions, silently grant permissions, disable Google Play Protect, and install applications from Google Play or APKPure. Disguised as a system app named ConfigAPKs, the malware collected device details, waited until the screen was unlocked to fetch additional payloads, and contacted the command-and-control domain api.adsnative123[.]com.
The malware was used to manipulate app-store rankings by inflating installs, registrations, and fraudulent reviews while also displaying ads and creating shortcuts to advertising sites. Infected devices were further abused to register accounts in legitimate apps using victims' Google or Facebook credentials, with activity reported most heavily in Russia during late 2019, followed by Brazil and India.

Pull IOCs and campaign context straight into your stack.
2 events from the most recent confirmed update back to the earliest known activity.
Trojan-Dropper.AndroidOS.Shopper.a was reported as most prevalent during October to November 2019, with the largest share of infected users in Russia, followed by Brazil and India. The malware was used to manipulate app-store rankings, inflate installs and registrations, and post fraudulent reviews.
Securelist published technical details on Trojan-Dropper.AndroidOS.Shopper.a, describing its abuse of Android AccessibilityService to grant permissions, disable Google Play Protect, install apps, and automate fraudulent actions. The report also identified command-and-control infrastructure including api.adsnative123[.]com and provided MD5 indicators of compromise.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 30 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.