logo

New Wonderland Android Malware with Bidirectional SMS-Stealing Capabilities Stealing OTPs

ID: 30612114-2454-5e29-b3e5-fbd01000f4d7

STIX ID: report--30612114-2454-5e29-b3e5-fbd01000f4d7

Feed Name: cybersecurityNews.com

Threat Score
78/100

Date Published: 2025-12-22

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

A new Android malware family named 'Wonderland' was discovered in October 2025 targeting Uzbekistan and Central Asia; it uses dropper apps to install an SMS stealer that employs heavy obfuscation, anti-analysis checks, and a WebSocket-based bidirectional C2 to execute USSD and SMS commands and suppress notifications, is distributed via Telegram-based social engineering, and is linked to criminal groups that reportedly earned over $2 million in 2025.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.