"Unlock the full potential of your smartphone" TROJAN

Link (Dangerous): KingRoot APK/PC - Best Android Root App | KingRoot Official Website (rootking.xyz)

Registered via NameCheap on February 13, 202 (Updated March 11, 2022) - Whois rootking.xyz

image

VirusTotal (No detections) - VirusTotal - File - 4f567fba68ea0c95eead0d86bef7339baf16b798c464949428abd961fadb85af

Any.Run - https://dl.dropboxusercontent.com/s/f7l1nz7jl3n1zp8/kingroot-setup-v3.5.0-x64_x86.rar - Interactive analysis - ANY.RUN

image

Program contains the Orcus RAT and a variant of the RedLine stealer.

Associated Facebook Account (Created April 13, 2022) - Free Android Tools (facebook.com)