logo

Russia arrests three for allegedly creating Mamont malware, tied to over 300 cybercrimes

ID: f203d8a9-2ba2-5671-b937-d7e935dd3bd5

STIX ID: report--f203d8a9-2ba2-5671-b937-d7e935dd3bd5

Feed Name: The Record from Recorded Future News

Threat Score
70/100

Date Published: 2025-03-27

Date Updated: 2026-05-01

...
...

Russian authorities arrested three suspects accused of developing the Mamont Android banking trojan, which is linked to more than 300 incidents. Mamont is distributed via Telegram (disguised as apps, videos, or order trackers), enables theft by abusing SMS-based banking (exfiltrating transaction messages and routing funds to attacker-controlled numbers and wallets), can collect device and financial message data, and spread to contacts; the activity has prompted proposed Russian legislation to restrict SMS sending during calls.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.