Telegram Users Beware! SpyMax RAT Attacking to Steal Sensitive Data
ID: 50515ff8-34b6-5522-bad9-b5fa51ef068d
STIX ID: report--50515ff8-34b6-5522-bad9-b5fa51ef068d
Feed Name: cybersecurityNews.com
SpyMax is an Android Remote Administration Tool delivered via a fake Telegram phishing page that lures victims to install ready.apk; once installed it requests Accessibility permissions to capture keystrokes, collect location and device data, compresses the stolen data with gzip, and exfiltrates it to a Command-and-Control server (154.213.65.28:7771). The report includes technical analysis, extracted commands and payloads, and IOCs (malicious URL, package name, and sample hash) and recommends patching and only installing apps from trusted stores.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
