Hackers use fake wedding invitations to spread Android malware in Southeast Asia
ID: f2b551e0-8dd0-52c3-9ad7-fe70ac5aee91
STIX ID: report--f2b551e0-8dd0-52c3-9ad7-fe70ac5aee91
Feed Name: The Record from Recorded Future News
Cybercriminals have been distributing an Android infostealer called Tria since mid‑2024 by sending fake wedding invitations via Telegram and WhatsApp to users in Malaysia and Brunei; victims are tricked into installing an app that exfiltrates SMS, emails (Gmail/Outlook), call logs, and messaging app data (WhatsApp/WhatsApp Business). The attackers use Telegram bots to collect stolen data and aim to hijack messaging accounts to spread the malware or conduct fraud; researchers observed similarities to a 2023 SMS‑theft campaign (UdangaSteal) but note distinct code and broader data targets for Tria.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
