Android Banking Malware deVixor Actively Targeting Users with Ransomware Capabilities
ID: 25c8ce84-1b27-55c9-ac52-1f983e607a3a
STIX ID: report--25c8ce84-1b27-55c9-ac52-1f983e607a3a
Feed Name: cybersecurityNews.com
deVixor is an evolving Android banking RAT observed in 700+ samples since October 2025 that intercepts SMS messages and injects JavaScript into WebViews to harvest banking and crypto credentials, uses Firebase and a separate C2 plus Telegram infrastructure for control and updates, and includes a ransomware module that locks devices demanding 50 TRX; it is distributed via fake automotive sites offering malicious APKs and primarily targets Iranian banks and cryptocurrency platforms.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
