SEEDSNATCHER Android Malware Attacking Users to Exfiltrate Sensitive Data and Execute Malicious Commands
ID: 422a6ada-15bc-56cc-8e3c-08cbfc1216e1
STIX ID: report--422a6ada-15bc-56cc-8e3c-08cbfc1216e1
Feed Name: cybersecurityNews.com
Threat Score
SeedSnatcher is an active, sophisticated Android malware campaign that targets cryptocurrency users by spoofing wallet import interfaces and validating BIP39 seed phrases to harvest ready-to-use recovery mnemonics; it uses overlay attacks, dynamic class loading, WebView injection, and WebSocket C2 (apivbe685jf829jf.a2decxd8syw7k.top), and is distributed via Telegram with agent-based tracking and commission-based operations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
