A malicious Android app disguised as an Adobe Flash Player update was found acting as a trojan downloader that silently fetched and installed additional malware on infected devices. Detected as Android/TrojanDownloader.Agent.JI, the app abused Android Accessibility Service permissions to mimic user clicks, conceal its actions behind a fake lock screen, and automatically download, install, execute, and grant elevated privileges to secondary payloads without the victim’s awareness.
The malware was distributed through compromised websites, including adult video pages, and through social media lures urging users to install a fake Flash update. After infection, it contacted a command-and-control server, transmitted device details, and received a URL for a follow-on app; in the observed case, the secondary payload was banking malware identified as Android/Spy.Banker.HD. Investigators said victims could spot the infection by checking for a rogue accessibility service named “Saving battery” and removing the fake Flash Player app, including revoking device administrator rights if necessary.

Pull IOCs and campaign context straight into your stack.
1 event from the most recent confirmed update back to the earliest known activity.
ESET Research reported a malicious Android app masquerading as an Adobe Flash Player update and detecting it as Android/TrojanDownloader.Agent.JI. The trojan was distributed via compromised websites and social media, abused Accessibility Service permissions to mimic clicks, and in an observed case downloaded banking malware detected as Android/Spy.Banker.HD.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.