Doctor Web cybersecurity experts: The malware has been downloaded from the official Android AppGallery. Main function: to subscribe users to paid mobile services.
The attack is part of the TA551 (Shathak) campaign. The xlsm file in the email zip attachment contacts internal URLs to download the dll, starting malware infection.
Two different emails but with the same xls attachment, which contacts a random link from an internal list and downloads the dll, starting malware infection.