This blog post is the continuation of our series on Operation Triangulation. The previous blog post can be found here : https://shindan.io/posts/audio_module_analysis/.
In this blogpost we will focus on the sms stealing module c2393fceab76776e19848c2ca3c84bea0ed224ac53206c48f1c5fd525ef66306
.
The module is pretty simple. It is opening the SMS database, executing several requests on it, and saving the compressed and encrypted output in a file.
...