CERT Polska details four-stage Android malware delivery chain
CERT Polska's 23 September 2026 report describes a campaign built around the Messenger Pro APK, removed from Google Play on 15 September. The malware delivers its payload in four stages, downloading and executing an encrypted DEX file after installation and controlling it via a C2 server.
- The loader and stage 1 made up just 0.552% of the base APK's DEX code
- Stage 1 ran only for 15 allowed country codes, including Poland
- Stage 2 downloaded a Base64 payload, inflated gzip and loaded DEX via InMemoryDexClassLoader
- The C2 encryption key was derived from the request URL via MD5, with the IV equal to the key
Read next
Security