Hacker News new | ask | show | jobs
by axsharma 1289 days ago
Same thought here. The domain appears to be associated with Ningbo Sunning Software, a Chinese vendor and likely a Mediatek partner than anything Android.
1 comments

Good catch after looking into it more this may be related to subcontractors providing vendors with malicious update tools that they then sign.

https://maldroid.github.io/docs/vb_2022.pdf

Good catch!