CSIDB logo
Incident

NoxPlayer

Incident posture

Attack window
Sep 2020
Location
Hong Kong
Status
Historical
CIA posture
Available to members
Updated
2025-10-29 00:00

Linked entities

Victim
NoxPlayer
Threat actors
1 actor
Sources
1 source

Timeline

Occurred
Sep 2020
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A threat actor compromised the official servers of an Android emulator provider, manipulating update delivery mechanisms to distribute malware-laced updates selectively to a small number of users in specific regions. The attackers deployed three distinct surveillance-focused malware families, targeting only five identified victims across Taiwan, Hong Kong, and Sri Lanka without apparent financial motives. The company implemented enhanced security measures including HTTPS enforcement, file integrity verification, and data encryption following the discovery. Researchers attributed the campaign to a known group based on technical similarities to prior supply-chain attacks, though the precise identity remains unconfirmed.

Motives

Detailed motive labels are available to members.

4 motives

TTPs

Detailed technique labels are available to members.

1 technique

Description

In September 2020, a threat actor compromised the official API and file-hosting servers of BigNox, the Hong Kong-based developer of the NoxPlayer Android emulator. Attackers manipulated download URLs for software updates on the compromised API server to distribute malicious updates to selected users. Evidence indicated the attackers maintained access to BigNox infrastructure for several months, though the malicious activity remained undetected until cybersecurity firm ESET investigated and disclosed the incident in February 2021. The attackers exclusively targeted a limited number of users across specific geographic regions, with confirmed victims located in Taiwan, Hong Kong, and Sri Lanka. ESET telemetry identified only five compromised devices receiving tampered updates during the campaign. The operation exhibited deliberate victim selection rather than broad exploitation, suggesting objectives focused on surveillance of particular individuals or organizations.

Three distinct malware families were delivered through the hijacked update mechanism, all exhibiting capabilities consistent with espionage operations rather than financial theft. Forensic analysis revealed similarities between these payloads and malware strains previously associated with a group tracked as Stellera, though ESET did not conclusively attribute the attack to any specific entity. BigNox implemented corrective measures after being notified, including enforcing HTTPS for all update deliveries, adding MD5 hash verification and digital signature validation for update files, and encrypting sensitive data on their servers. The company confirmed no widespread compromise of its user base occurred due to the highly targeted nature of the attack. ESET published technical indicators and remediation guidance for affected users while noting the absence of observable financial motives in the campaign’s execution.

Sources

Sources available to members: 1 source.

CSIDB