Researchers tied multiple Android threats to the Ztorg malware family, including trojanized apps such as "Cool Video Player," "Magic browser," and "Noise Detector". The malware used anti-analysis checks to avoid Android SDK emulators and common sandbox environments, then contacted command-and-control servers including bbs.tihalf.com and alla.tihalf.com with encrypted device data. In one infection chain, the app decrypted server responses, downloaded a secondary APK, decoded it, stored it as dba.jar, and loaded it invisibly with DexClassLoader, confirming a staged delivery model designed to hide malicious behavior from users and analysts.
Separate Ztorg-linked samples distributed through Google Play were installed more than 60,000 times before removal and shifted monetization from rooting toward premium SMS fraud and likely WAP billing abuse, using IMSI-derived carrier data to tailor activity by country and operator. Other Ztorg payloads went further by lowering SELinux protections, attempting to root devices, replacing system binaries such as /system/bin/debuggerd, and silently installing additional apps and executables for persistence. Analysts said the family combined obfuscation, encrypted payload delivery, rooting components, and stealthy monetization modules, making infections difficult to detect and remove.

Pull IOCs and campaign context straight into your stack.
5 events from the most recent confirmed update back to the earliest known activity.
The malicious Android app "Magic browser," later linked to a Ztorg Trojan-SMS campaign, was uploaded to Google Play. It was subsequently installed more than 50,000 times before removal.
Fortinet reported that the Android/Ztorg.AM!tr sample it analyzed was detected on January 20, 2017. The sample masqueraded as "Cool Video Player" and acted as a first-stage downloader.
Two malicious Google Play apps, "Magic browser" and "Noise Detector," were distributed as Trojan-SMS.AndroidOS.Ztorg.a. Together they amassed more than 60,000 installs and were used for premium SMS fraud, SMS deletion, and likely WAP billing abuse.
The Ztorg, also known as Qysly, Android malware family first appeared. Later 2017 samples analyzed by Fortinet were identified as variants of this family.
After the malware was reported, Google removed the malicious "Magic browser" and "Noise Detector" apps from Google Play. The apps had been used to distribute Ztorg-linked SMS fraud malware.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 19 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
3 references tracked. Mallory keeps watching after this page renders.
securelist.com
Open sourceblog.fortinet.com
Open sourceblog.fortinet.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.