Qwizzserial Android Malware Poses as Legit Apps to Steal Banking Info and Bypass 2FA via SMS Interception
ID: 208c9995-e20d-5487-a6a0-38c186b601a1
STIX ID: report--208c9995-e20d-5487-a6a0-38c186b601a1
Feed Name: Cyber Press
Qwizzserial is a currently active Android malware campaign targeting users in Uzbekistan by distributing sideloaded malicious APKs via Telegram channels and bots; it requests SMS/phone permissions, harvests phone and card data, intercepts OTPs to bypass SMS-based 2FA, and exfiltrates data to Telegram bots or via HTTP to gate servers. Group-IB attributes ~100,000 infections and documented financial losses (~US$62,000) over three months, notes advanced obfuscation and persistence techniques, and provides indicators (domains and file hashes) and mitigation recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
