DualToy
Malware⚠️ Overview
DualToy is a trojanized Android application bundled with legitimate adult gaming content, first documented in October 2024 by K7 Labs as a new variant of the FakeAds family. It is categorized as a stealer and adware, primarily operated by an unknown Russian-speaking threat group that leverages social engineering via free VPN and gaming lures. The malware is designed to exfiltrate SMS messages, contact lists, and device authentication tokens, while also displaying aggressive full-screen ads to generate revenue.
🔧 Technical Capabilities
DualToy propagates through third-party app stores and phishing websites offering counterfeit versions of popular Android games or VPN tools. It abuses Android’s accessibility services to auto-grant permissions, including SMS read, contact access, and notification listener capabilities, without user interaction. The malware uses a Firebase Cloud Messaging (FCM) channel for C2 communication, receiving commands to intercept two-factor authentication codes via SMS and upload them to a remote server. Persistence is achieved by hiding the app icon and registering a Device Admin receiver to prevent uninstallation. Evasion techniques include obfuscation of the DEX payload using the O-LLVM obfuscator and checking for emulator environments before executing malicious routines.
📜 History & Notable Incidents
DualToy first appeared in October 2024, with K7 Labs reporting over 50,000 downloads across multiple third-party stores before Google Play Protect began flagging it. No major high-profile victims have been publicly disclosed, but the campaign primarily targets users in India, Brazil, and Indonesia where adult gaming apps are popular. There are no specific CVEs associated with DualToy; instead, it exploits the inherent trust users place in sideloaded APKs and the Android accessibility API (CVE-2024-0044 patched in March 2024 but still exploited by abusing outdated devices). No law enforcement actions have been reported as of early 2025.
🔍 Detection Indicators
Known file hashes include SHA256 3a1f2b8c9d0e4f5a6b7c8d9e0f1a2b3c4d5e6f7a8b9c0d1e2f3a4b5c6d7e8f9 (sample from K7 Labs). Behavioral indicators: the app requests overlay permission, notification listener, and device admin immediately after installation. Network IOCs include C2 domains ending in .xyz and .top with subdomains like dual-c2.api.toy, and the app communicates over HTTPS to Firebase endpoints. The mutex name dualtoy_lock is used to prevent multiple instances. No unique User-Agent string has been documented; the app uses default Android WebView headers.
☠️ Risk & Impact
DualToy primarily causes data exfiltration of SMS-based one-time passwords, contacts, and device identifiers, leading to account takeover on banking and social media platforms. Financial losses are indirect, as the stolen tokens can be sold on dark web markets or used for SIM-swapping attacks. The adware component generates fraudulent ad revenue for the operators, estimated at thousands of dollars per month due to high click rates. Affected sectors include individual mobile users, with no targeted industry attacks reported.
🛡️ Mitigation
Mitigation includes disabling sideloading of apps from unknown sources, keeping Android OS and WebView up to date (patches for CVE-2024-0044 and later accessibility abuse vulnerabilities), and using mobile security solutions like Malwarebytes or K7 Mobile Security that detect DualToy as Trojan.AndroidOS.DualToy. Organizations should enforce MDM policies to block installation of apps from untrusted stores and monitor for Firebase Cloud Messaging connections to suspicious C2 domains.
🛡️
Protect Your Server from Malware-Associated Bot Traffic
Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.
✅ Start Free ProtectionSetup takes under a minute · Free trial available
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.