logo

Hackers use fake wedding invitations to spread Android malware in Southeast Asia

ID: f2b551e0-8dd0-52c3-9ad7-fe70ac5aee91

STIX ID: report--f2b551e0-8dd0-52c3-9ad7-fe70ac5aee91

Feed Name: The Record from Recorded Future News

Threat Score
70/100

Date Published: 2025-01-31

Date Updated: 2026-05-01

...
...

Cybercriminals have been distributing an Android infostealer called Tria since mid‑2024 by sending fake wedding invitations via Telegram and WhatsApp to users in Malaysia and Brunei; victims are tricked into installing an app that exfiltrates SMS, emails (Gmail/Outlook), call logs, and messaging app data (WhatsApp/WhatsApp Business). The attackers use Telegram bots to collect stolen data and aim to hijack messaging accounts to spread the malware or conduct fraud; researchers observed similarities to a 2023 SMS‑theft campaign (UdangaSteal) but note distinct code and broader data targets for Tria.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.