Loapi Malware
Loapi Malware
Loapi Malware
• What is Loapi?
• Distribution
• Infection
• Self-protection
• Modules
• Layered architecture
• Manifest analysis
• Conclusion and protection methods
TECHNICAL UNIVERSITY OF CLUJ-NAPOCA 2
What is Loapi?
• This module is used for hidden JavaScript code execution on web pages with
WAP billing in order to subscribe the user to various services (together with
the ad module)
• WAP billing = mechanism for consumers to purchase content from WAP
(Wireless Application Protocol) sites that is charged directly to the mobile
phone bill.
• Together with the ad module, this module tried to open around 28,000 unique
URLs during a 24-hour experiment (Kaspersky labs experiment).
• https://securelist.com/jack-of-all-trades/83470/
• https://www.kaspersky.com/blog/loapi-trojan/20510/
• https://www.virustotal.com/en/file/f24f90b8c71fabed544895f14d2f10b0
d3b37eec41521841fe623fa9a1c5ebad/analysis/