New Wonderland Android Malware with Bidirectional SMS-Stealing Capabilities Stealing OTPs
ID: 30612114-2454-5e29-b3e5-fbd01000f4d7
STIX ID: report--30612114-2454-5e29-b3e5-fbd01000f4d7
Feed Name: cybersecurityNews.com
Threat Score
A new Android malware family named 'Wonderland' was discovered in October 2025 targeting Uzbekistan and Central Asia; it uses dropper apps to install an SMS stealer that employs heavy obfuscation, anti-analysis checks, and a WebSocket-based bidirectional C2 to execute USSD and SMS commands and suppress notifications, is distributed via Telegram-based social engineering, and is linked to criminal groups that reportedly earned over $2 million in 2025.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
