LANDFALL Android Spyware SELinux Policy Manipulation
Detects the LANDFALL Android spyware manipulating SELinux policy by preloading a malicious shared object and passing a path to the 'l.so' policy manipulator component via the PRELOAD_PATH environment variable.
Microsoft Sentinel (KQL)

