{"id":41873,"date":"2021-07-21T00:00:00","date_gmt":"2021-07-21T00:00:00","guid":{"rendered":"https:\/\/www.trendmicro.com\/en_us\/research\/21\/g\/strongpity-apt-group-deploys-android-malware-for-the-first-time.html"},"modified":"2021-07-21T00:00:00","modified_gmt":"2021-07-21T00:00:00","slug":"strongpity-apt-group-deploys-android-malware-for-the-first-time-sr-threat-researcher-mobile-threats-analyst","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/strongpity-apt-group-deploys-android-malware-for-the-first-time-sr-threat-researcher-mobile-threats-analyst\/","title":{"rendered":"StrongPity APT Group Deploys Android Malware for the First Time Sr. Threat Researcher Mobile Threats Analyst"},"content":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/21\/g\/strongpity-apt-group-deploys-android-malware-for-the-first-time\/strongpity-android-641.png\"><\/p>\n<div><img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/21\/g\/strongpity-apt-group-deploys-android-malware-for-the-first-time\/strongpity-android-641.png\" class=\"ff-og-image-inserted\"><\/div>\n<p>If we examine another StrongPity sample (12818a96211b7c47863b109be63e951075cf6a41652464a584dd2f26010f7535), the logic is similar \u2014 it drops a normal installer into the Temp directory and creates a directory for dropped malicious files.<\/p>\n<p>Here are three notable similarities between the Windows sample and the Android sample:<\/p>\n<p>1.&nbsp;&nbsp;&nbsp; They all disguised as normal apps by utilizing the original clean applications \u2014 the Android sample repacks the original one into a trojanized version, while the Windows sample uses a trojanized installer packed with the original program.<\/p>\n<p>2.&nbsp;&nbsp;&nbsp; Both collect and exfiltrate files from the infected device.<\/p>\n<p>3.&nbsp;&nbsp;&nbsp; Both are highly modular. The Windows sample has a standalone Exfiltration and File Search module, a feature that could also be seen in the latest test Android sample.<\/p>\n<p>We found several clues that link the malicious Android samples with the StrongPity threat actor.<\/p>\n<p>The sample 74582c3d920332117541a9bbc6b8995fbe7e1aff communicates with the URL &nbsp;https:\/\/www.upn-sec3-msd[.]com\/ProxyServer\/service\/. &nbsp;The domain name \u201cupn-sec3-msd[.]com\u201d was mentioned in <a href=\"https:\/\/cybersecurity.att.com\/blogs\/labs-research\/newly-identified-strongpity-operations\">another StrongPity report<\/a>.<\/p>\n<p>The domain naming pattern and domain acquisition techniques are quite similar. For example, the <a href=\"https:\/\/blog.talosintelligence.com\/2020\/06\/promethium-extends-with-strongpity3.html\">domain names<\/a> used by StrongPity in 2020 have a domain naming pattern similar to the domains used by the identified Android samples.<\/p>\n<p>One of the domain names, networktopologymaps[.]com, was likely bought when registration at Gandi expired. The domain was acquired via the Porkbun network registrar.<\/p>\n<p>This is similar to the domain hostoperationsystems[.]com, which was previously mentioned in the Talos report. This domain was also acquired via Porkbun and features a comparable domain naming pattern.<\/p>\n<p>Another notable point of correlation to StrongPity is the list of file extensions, which we have seen in Android samples. A similar list of the file extensions for the files is presented in variants of the trojan for Windows systems. For example, one of the samples that we had examined earlier,&nbsp;gathers files with the following extensions:<\/p>\n<ul>\n<li><span class=\"rte-red-bullet\">.7z<\/span><\/li>\n<li><span class=\"rte-red-bullet\">.asc<\/span><\/li>\n<li><span class=\"rte-red-bullet\">.dgs<\/span><\/li>\n<li><span class=\"rte-red-bullet\">.doc<\/span><\/li>\n<li><span class=\"rte-red-bullet\">.docx<\/span><\/li>\n<li><span class=\"rte-red-bullet\">.gpg<\/span><\/li>\n<li><span class=\"rte-red-bullet\">.pdf<\/span><\/li>\n<li><span class=\"rte-red-bullet\">.pgp<\/span><\/li>\n<li><span class=\"rte-red-bullet\">.ppt<\/span><\/li>\n<li><span class=\"rte-red-bullet\">.pptx<\/span><\/li>\n<li><span class=\"rte-red-bullet\">.rar<\/span><\/li>\n<li><span class=\"rte-red-bullet\">.rjv<\/span><\/li>\n<li><span class=\"rte-red-bullet\">.rms<\/span><\/li>\n<li><span class=\"rte-red-bullet\">.rtf<\/span><\/li>\n<li><span class=\"rte-red-bullet\">.sft<\/span><\/li>\n<li><span class=\"rte-red-bullet\">.tc<\/span><\/li>\n<li><span class=\"rte-red-bullet\">.txt<\/span><\/li>\n<li><span class=\"rte-red-bullet\">.xls<\/span><\/li>\n<li><span class=\"rte-red-bullet\">.xlsx<\/span><\/li>\n<\/ul>\n<p>As we previously mentioned, there are no public reports of the StrongPity threat actor using malicious Android applications in the attack. However, we examined the trojan code-embedding techniques as well as the trojan functionality of the malicious code written by the same threat actor for Windows platforms, and we have identified some similar patterns. This leads us to believe that these could belong to the same threat actor.<\/p>\n<h2><span class=\"body-subhead-title\">StrongPity actively develops new malicious android apps<\/span><\/h2>\n<p>We believe that the StrongPity Threat actor is actively developing backdoors for Android. Based on the test sample that we have identified, we can see that the threat actor attempts several techniques to lure potential victims: repackaged applications, compromised websites, and fake variants of popular applications.<\/p>\n<p>Based on the additional functionalities that we identified in the fake Samsung security service application (75dc2829abb951ff970debfba9f66d4d7c6b7c48a823a911dd5874f74ac63d7b), we think that among the APK files that we had identified, the repackaged applications are bundled with the first version of the Android trojan, while the fake application could be a work in progress for the next version of the tool.<\/p>\n<p>In the second version, we observed the threat actor developed and included some additional components and as well as added support for more message types.<\/p>\n<p>The following table shows the types that the threat actor has defined.<\/p>\n<table border=\"1\" cellspacing=\"0\" cellpadding=\"0\" width=\"100%\">\n<tbody readability=\"2\">\n<tr>\n<td>\n<p>Message type<\/p>\n<\/td>\n<td width=\"312\" valign=\"top\">\n<p>Details<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td width=\"312\" valign=\"top\">\n<p>MSG_ADD_MODULE<\/p>\n<\/td>\n<td width=\"312\" valign=\"top\">\n<p>Add a new module<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td width=\"312\" valign=\"top\">\n<p>MSG_GET_MODULE<\/p>\n<\/td>\n<td width=\"312\" valign=\"top\">\n<p>Get the module instance<\/p>\n<\/td>\n<\/tr>\n<tr readability=\"3\">\n<td width=\"312\" valign=\"top\">\n<p>MSG_DEL_MODULE<\/p>\n<\/td>\n<td width=\"312\" valign=\"top\" readability=\"5\">\n<p>Delete module file under &lt;DIR&gt;\/.android\/.li\/&lt;module name&gt;<\/p>\n<\/td>\n<\/tr>\n<tr readability=\"3\">\n<td width=\"312\" valign=\"top\">\n<p>MSG_DEL_APK<\/p>\n<\/td>\n<td width=\"312\" valign=\"top\" readability=\"5\">\n<p>Delete the APK file under the download directory<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td width=\"312\" valign=\"top\">\n<p>MSG_START_MODULES<\/p>\n<\/td>\n<td width=\"312\" valign=\"top\">\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h5>Table 2. Message types defined by the threat actor<\/h5>\n<p>In this version, MSG_COLLECT is no longer present \u2014 we think they replaced it with MSG_START_MODULES, a message used to read all module names from the shared preference, and start\/initialize them one by one.<\/p>\n<p>We were not able to get access to these modules, but based on some of the code functionality that we observed, we believe that these modules are designed to collect data from the victim\u2019s devices and write the collected data into a local SQLite db data file. However, we were not able to find any of these modules in the wild.<\/p>\n<p>There are also several other key differences between version 1 and version 2 of the trojan:<\/p>\n<ul>\n<li><span class=\"rte-red-bullet\">The message Handler for heartbeat message in version 2 is now split into two messages: heartbeat and taken_config. Either of these messages can receive a response from the C&amp;C server and decrypt the response to update the local configuration, similarly to the version 1.<\/span><\/li>\n<li><span class=\"rte-red-bullet\">Version 2 uses different AES encryption keys: &nbsp;key(&#8220;aaaanothingimpossiblebbb&#8221;), and AES IV(&#8220;aaaanothingimpos&#8221;)<\/span><\/li>\n<li><span class=\"rte-red-bullet\">ScreenReceiver class is added to the second version of the trojan. The purpose of this Receiver is to start the malicious service via Screen_On and Screen_Off events.<\/span><\/li>\n<li><span class=\"rte-red-bullet\">Version 2 has an ability to execute \u201csu\u201d command, if the device is rooted.&nbsp;The main usage of the root privilege here is that it could grant permissions silently. Such permissions include accessibility, notification and other. However, we did not find any evidence that the sample would attempt to root the device. <\/span><\/li>\n<li><span class=\"rte-red-bullet\">Two components were added in version 2 for accessibility and notification.<\/span><\/li>\n<li><span class=\"rte-red-bullet\">Version 2 uses SQLite to store collected data. Furthermore, it no longer uses ZIP.<\/span><\/li>\n<li><span class=\"rte-red-bullet\">In Version 2, the extra modules used in \u201cMSG_START_MODULES\u201d are downloaded from the C&amp;C server via either the heartbeat or taken_config message. It\u2019s possible that these modules are decompressed as part of the response into &lt;DIR&gt;\/.android\/.li and consequentially executed.<\/span><\/li>\n<\/ul>\n<p>This investigation has provided evidence to attribute the Android malware sample, which was posted on the Syrian e-Gov website, to the StrongPity threat group. We were also able to identify additional Android trojan files and correlate these malicious Android applications with existing public reports based on their similarities to the threat actor\u2019s TTPs and network infrastructure they used.<\/p>\n<p>Although there are no previously known malicious Android applications attributed to the StrongPity group, we strongly believe that the threat actor is in the process of actively developing new malicious components that can be used to target Android platforms.<\/p>\n<p>We believe that the threat actor is exploring multiple ways of delivering the applications to potential victims, such as using fake apps and using compromised websites as watering holes to trick users into installing malicious applications. Typically, these websites would require its users to download the applications directly onto their devices. In order to do so, these users would be required to enable installation of the applications from \u201cunknown sources\u201d on their devices. This bypasses the \u201ctrust-chain\u201d of the Android ecosystem and makes it easier for an attacker to deliver additional malicious components.<\/p>\n<h2><span class=\"body-subhead-title\"><\/span><\/h2>\n<table border=\"1\" cellspacing=\"0\" cellpadding=\"0\" width=\"100%\">\n<tbody readability=\"11\">\n<tr>\n<td>\n<p><b>SHA256<\/b><\/p>\n<\/td>\n<td width=\"106\" valign=\"top\">\n<p><b>Description<\/b><\/p>\n<\/td>\n<td width=\"15\" valign=\"top\">\n<p><b>Detection<\/b><\/p>\n<\/td>\n<\/tr>\n<tr readability=\"6\">\n<td width=\"498\" valign=\"top\" readability=\"5\">\n<p>fd1aac87399ad22234c503d8adb2ae9f0d950b6edf4456b1515a30100b5656a7<\/p>\n<\/td>\n<td width=\"106\" valign=\"top\" readability=\"5\">\n<p>The trojanized version of the Syria eGov Application<\/p>\n<\/td>\n<td width=\"15\" valign=\"top\">\n<p>AndroidOS_StrongPity.HRX<\/p>\n<\/td>\n<\/tr>\n<tr readability=\"6\">\n<td width=\"498\" valign=\"top\" readability=\"5\">\n<p>374d92f553c28e9dad1aa7f5d334a07dede1e5ad19c3766efde74290d0c49afb<\/p>\n<\/td>\n<td width=\"106\" valign=\"top\" readability=\"5\">\n<p>Sample repackaged from Kingoroot<\/p>\n<\/td>\n<td width=\"15\" valign=\"top\">\n<p>AndroidOS_StrongPity.HRX<\/p>\n<\/td>\n<\/tr>\n<tr readability=\"9.5\">\n<td width=\"498\" valign=\"top\" readability=\"8\">\n<p>a9378a5469319faffc48f3aa70f5b352d5acb7d361c5177a9aac90d9c58bb628<\/p>\n<p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;<\/p>\n<\/td>\n<td width=\"106\" valign=\"top\" readability=\"5\">\n<p>Sample repackaged from net.cybertik.wifi<\/p>\n<\/td>\n<td width=\"15\" valign=\"top\">\n<p>AndroidOS_StrongPity.HRX<\/p>\n<\/td>\n<\/tr>\n<tr readability=\"3\">\n<td width=\"498\" valign=\"top\" readability=\"5\">\n<p>be9214a5804632004f7fd5b90fbac3e23f44bb7f0a252b8277dd7e9d8b8a52f3<\/p>\n<\/td>\n<td width=\"106\" valign=\"top\">\n<p>Repackaged from Snaptube<\/p>\n<\/td>\n<td width=\"15\" valign=\"top\">\n<p>AndroidOS_StrongPity.HRX<\/p>\n<\/td>\n<\/tr>\n<tr readability=\"3\">\n<td width=\"498\" valign=\"top\" readability=\"5\">\n<p>596257ef017b02ba6961869d78a2317500a45f00c76682a22bbdbd3391857b5d<\/p>\n<\/td>\n<td width=\"106\" valign=\"top\">\n<p>Repackaged from Snaptube<\/p>\n<\/td>\n<td width=\"15\" valign=\"top\">\n<p>AndroidOS_StrongPity.HRX<\/p>\n<\/td>\n<\/tr>\n<tr readability=\"6\">\n<td width=\"498\" valign=\"top\" readability=\"5\">\n<p>75dc2829abb951ff970debfba9f66d4d7c6b7c48a823a911dd5874f74ac63d7b<\/p>\n<\/td>\n<td width=\"106\" valign=\"top\" readability=\"5\">\n<p>Fake Samsung Security Service sample<\/p>\n<\/td>\n<td width=\"15\" valign=\"top\">\n<p>AndroidOS_StrongPity.HRX<\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2><b data-rte-class=\"rte-temp\"><span class=\"body-subhead-title\"><br \/>Network C&amp;C Infrastructure<\/span><\/b><\/h2>\n<table border=\"1\" cellspacing=\"0\" cellpadding=\"0\" width=\"100%\">\n<tbody readability=\"9\">\n<tr>\n<td width=\"438\" valign=\"top\">\n<p><b>SHA256<\/b><\/p>\n<\/td>\n<td width=\"165\" valign=\"top\">\n<p><b>Domain<\/b><\/p>\n<\/td>\n<td width=\"15\" valign=\"top\">\n<p><b>Detection<\/b><\/p>\n<\/td>\n<\/tr>\n<tr readability=\"3\">\n<td width=\"438\" valign=\"top\" readability=\"5\">\n<p>fd1aac87399ad22234c503d8adb2ae9f0d950b6edf4456b1515a30100b5656a7<\/p>\n<\/td>\n<td width=\"165\" valign=\"top\">\n<p>Internetwideband[.]com<\/p>\n<\/td>\n<td width=\"15\" valign=\"top\">\n<p>AndroidOS_StrongPity.HRX<\/p>\n<\/td>\n<\/tr>\n<tr readability=\"3\">\n<td width=\"438\" valign=\"top\" readability=\"5\">\n<p>374d92f553c28e9dad1aa7f5d334a07dede1e5ad19c3766efde74290d0c49afb<\/p>\n<\/td>\n<td width=\"165\" valign=\"top\">\n<p>upeg-system-app[.]com<\/p>\n<\/td>\n<td width=\"15\" valign=\"top\">\n<p>AndroidOS_StrongPity.HRX<\/p>\n<\/td>\n<\/tr>\n<tr readability=\"9.5\">\n<td width=\"438\" valign=\"top\" readability=\"8\">\n<p>a9378a5469319faffc48f3aa70f5b352d5acb7d361c5177a9aac90d9c58bb628<\/p>\n<p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;<\/p>\n<\/td>\n<td width=\"165\" valign=\"top\" readability=\"5\">\n<p>networktopologymaps[.]com<\/p>\n<\/td>\n<td width=\"15\" valign=\"top\">\n<p>AndroidOS_StrongPity.HRX<\/p>\n<\/td>\n<\/tr>\n<tr readability=\"6\">\n<td width=\"438\" valign=\"top\" readability=\"5\">\n<p>be9214a5804632004f7fd5b90fbac3e23f44bb7f0a252b8277dd7e9d8b8a52f3<\/p>\n<\/td>\n<td width=\"165\" valign=\"top\" readability=\"5\">\n<p>networktopologymaps[.]com<\/p>\n<\/td>\n<td width=\"15\" valign=\"top\">\n<p>AndroidOS_StrongPity.HRX<\/p>\n<\/td>\n<\/tr>\n<tr readability=\"3\">\n<td width=\"438\" valign=\"top\" readability=\"5\">\n<p>596257ef017b02ba6961869d78a2317500a45f00c76682a22bbdbd3391857b5d<\/p>\n<\/td>\n<td width=\"165\" valign=\"top\">\n<p>upeg-system-app[.]com<\/p>\n<\/td>\n<td width=\"15\" valign=\"top\">\n<p>AndroidOS_StrongPity.HRX<\/p>\n<\/td>\n<\/tr>\n<tr readability=\"3\">\n<td width=\"438\" valign=\"top\" readability=\"5\">\n<p>75dc2829abb951ff970debfba9f66d4d7c6b7c48a823a911dd5874f74ac63d7b<\/p>\n<\/td>\n<td width=\"165\" valign=\"top\">\n<p>upn-sec3-msd[.]com<\/p>\n<\/td>\n<td width=\"15\" valign=\"top\">\n<p>AndroidOS_StrongPity.HRX<\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p> Read More <a href=\"https:\/\/www.trendmicro.com\/en_us\/research\/21\/g\/strongpity-apt-group-deploys-android-malware-for-the-first-time.html\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>We recently conducted an investigation into a malicious Android malware sample, which we believe can be attributed to the StrongPity APT group, that was posted on the Syrian e-Gov website. To the best of our knowledge, this is the first time that the group has been publicly observed using malicious Android applications as part of its attacks. Read More HERE&#8230;<\/p>\n","protected":false},"author":2,"featured_media":41874,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[61],"tags":[9471,9461,163,842],"class_list":["post-41873","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-trendmicro","tag-apttargeted-attacks","tag-articles-news-reports","tag-mobile","tag-research"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.8 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>StrongPity APT Group Deploys Android Malware for the First Time Sr. Threat Researcher Mobile Threats Analyst 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/strongpity-apt-group-deploys-android-malware-for-the-first-time-sr-threat-researcher-mobile-threats-analyst\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"StrongPity APT Group Deploys Android Malware for the First Time Sr. Threat Researcher Mobile Threats Analyst 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/strongpity-apt-group-deploys-android-malware-for-the-first-time-sr-threat-researcher-mobile-threats-analyst\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2021-07-21T00:00:00+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/07\/strongpity-apt-group-deploys-android-malware-for-the-first-time-sr-threat-researcher-mobile-threats-analyst.png\" \/>\n\t<meta property=\"og:image:width\" content=\"641\" \/>\n\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"8 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/strongpity-apt-group-deploys-android-malware-for-the-first-time-sr-threat-researcher-mobile-threats-analyst\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/strongpity-apt-group-deploys-android-malware-for-the-first-time-sr-threat-researcher-mobile-threats-analyst\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"StrongPity APT Group Deploys Android Malware for the First Time Sr. Threat Researcher Mobile Threats Analyst\",\"datePublished\":\"2021-07-21T00:00:00+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/strongpity-apt-group-deploys-android-malware-for-the-first-time-sr-threat-researcher-mobile-threats-analyst\\\/\"},\"wordCount\":1622,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/strongpity-apt-group-deploys-android-malware-for-the-first-time-sr-threat-researcher-mobile-threats-analyst\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/07\\\/strongpity-apt-group-deploys-android-malware-for-the-first-time-sr-threat-researcher-mobile-threats-analyst.png\",\"keywords\":[\"APT&amp;Targeted Attacks\",\"Articles, News, Reports\",\"Mobile\",\"Research\"],\"articleSection\":[\"TrendMicro\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/strongpity-apt-group-deploys-android-malware-for-the-first-time-sr-threat-researcher-mobile-threats-analyst\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/strongpity-apt-group-deploys-android-malware-for-the-first-time-sr-threat-researcher-mobile-threats-analyst\\\/\",\"name\":\"StrongPity APT Group Deploys Android Malware for the First Time Sr. Threat Researcher Mobile Threats Analyst 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/strongpity-apt-group-deploys-android-malware-for-the-first-time-sr-threat-researcher-mobile-threats-analyst\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/strongpity-apt-group-deploys-android-malware-for-the-first-time-sr-threat-researcher-mobile-threats-analyst\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/07\\\/strongpity-apt-group-deploys-android-malware-for-the-first-time-sr-threat-researcher-mobile-threats-analyst.png\",\"datePublished\":\"2021-07-21T00:00:00+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/strongpity-apt-group-deploys-android-malware-for-the-first-time-sr-threat-researcher-mobile-threats-analyst\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/strongpity-apt-group-deploys-android-malware-for-the-first-time-sr-threat-researcher-mobile-threats-analyst\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/strongpity-apt-group-deploys-android-malware-for-the-first-time-sr-threat-researcher-mobile-threats-analyst\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/07\\\/strongpity-apt-group-deploys-android-malware-for-the-first-time-sr-threat-researcher-mobile-threats-analyst.png\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/07\\\/strongpity-apt-group-deploys-android-malware-for-the-first-time-sr-threat-researcher-mobile-threats-analyst.png\",\"width\":641,\"height\":350},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/strongpity-apt-group-deploys-android-malware-for-the-first-time-sr-threat-researcher-mobile-threats-analyst\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"APT&amp;Targeted Attacks\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/tag\\\/apttargeted-attacks\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"StrongPity APT Group Deploys Android Malware for the First Time Sr. Threat Researcher Mobile Threats Analyst\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"StrongPity APT Group Deploys Android Malware for the First Time Sr. Threat Researcher Mobile Threats Analyst 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/strongpity-apt-group-deploys-android-malware-for-the-first-time-sr-threat-researcher-mobile-threats-analyst\/","og_locale":"en_US","og_type":"article","og_title":"StrongPity APT Group Deploys Android Malware for the First Time Sr. Threat Researcher Mobile Threats Analyst 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/strongpity-apt-group-deploys-android-malware-for-the-first-time-sr-threat-researcher-mobile-threats-analyst\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2021-07-21T00:00:00+00:00","og_image":[{"width":641,"height":350,"url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/07\/strongpity-apt-group-deploys-android-malware-for-the-first-time-sr-threat-researcher-mobile-threats-analyst.png","type":"image\/png"}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"8 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/strongpity-apt-group-deploys-android-malware-for-the-first-time-sr-threat-researcher-mobile-threats-analyst\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/strongpity-apt-group-deploys-android-malware-for-the-first-time-sr-threat-researcher-mobile-threats-analyst\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"StrongPity APT Group Deploys Android Malware for the First Time Sr. Threat Researcher Mobile Threats Analyst","datePublished":"2021-07-21T00:00:00+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/strongpity-apt-group-deploys-android-malware-for-the-first-time-sr-threat-researcher-mobile-threats-analyst\/"},"wordCount":1622,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/strongpity-apt-group-deploys-android-malware-for-the-first-time-sr-threat-researcher-mobile-threats-analyst\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/07\/strongpity-apt-group-deploys-android-malware-for-the-first-time-sr-threat-researcher-mobile-threats-analyst.png","keywords":["APT&amp;Targeted Attacks","Articles, News, Reports","Mobile","Research"],"articleSection":["TrendMicro"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/strongpity-apt-group-deploys-android-malware-for-the-first-time-sr-threat-researcher-mobile-threats-analyst\/","url":"https:\/\/www.threatshub.org\/blog\/strongpity-apt-group-deploys-android-malware-for-the-first-time-sr-threat-researcher-mobile-threats-analyst\/","name":"StrongPity APT Group Deploys Android Malware for the First Time Sr. Threat Researcher Mobile Threats Analyst 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/strongpity-apt-group-deploys-android-malware-for-the-first-time-sr-threat-researcher-mobile-threats-analyst\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/strongpity-apt-group-deploys-android-malware-for-the-first-time-sr-threat-researcher-mobile-threats-analyst\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/07\/strongpity-apt-group-deploys-android-malware-for-the-first-time-sr-threat-researcher-mobile-threats-analyst.png","datePublished":"2021-07-21T00:00:00+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/strongpity-apt-group-deploys-android-malware-for-the-first-time-sr-threat-researcher-mobile-threats-analyst\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/strongpity-apt-group-deploys-android-malware-for-the-first-time-sr-threat-researcher-mobile-threats-analyst\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/strongpity-apt-group-deploys-android-malware-for-the-first-time-sr-threat-researcher-mobile-threats-analyst\/#primaryimage","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/07\/strongpity-apt-group-deploys-android-malware-for-the-first-time-sr-threat-researcher-mobile-threats-analyst.png","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/07\/strongpity-apt-group-deploys-android-malware-for-the-first-time-sr-threat-researcher-mobile-threats-analyst.png","width":641,"height":350},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/strongpity-apt-group-deploys-android-malware-for-the-first-time-sr-threat-researcher-mobile-threats-analyst\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"APT&amp;Targeted Attacks","item":"https:\/\/www.threatshub.org\/blog\/tag\/apttargeted-attacks\/"},{"@type":"ListItem","position":3,"name":"StrongPity APT Group Deploys Android Malware for the First Time Sr. Threat Researcher Mobile Threats Analyst"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/41873","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=41873"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/41873\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media\/41874"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=41873"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=41873"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=41873"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}