Sample Details:

SHA256 Hash: 75f42606987885c36a1576c06ec0e012967bd7e4c03f5754d967575da43589b4

Package Name: com.dufusobudijige.wita

Application Name: Chrome

Components Analysis

Accessibility Service

HTTP Communication

Commands

Here are the most commonly used commands that I found in the app.

Evasion Techniques

Encryption & Decryption

Conclusion

This was an interesting sample to analyze. Particularly the clipboard hijacking functionality was something I have never seen before. This app gave me a new perspective on how malware authors are using Accessibility Service to perform malicious activities. Hopefully, this writeup will help you understand the inner workings of this malware family.

Thanks for reading.