logo

Android Banking Trojan Spreads via WhatsApp Using Fake KYC Lures

ID: 4430fc2c-7a64-5d69-9281-73811ec287ba

STIX ID: report--4430fc2c-7a64-5d69-9281-73811ec287ba

Feed Name: Cyber Press

Threat Score
75/100

Date Published: 2026-04-28

Date Updated: 2026-04-28

Author: Varshini

...
...

An active Android banking trojan circulated via WhatsApp masquerades as a mandatory "Banking KYC" app to phish Indian users; it employs a two-stage dropper, native-code obfuscation, hidden secondary payload, a local full-tunnel VPN and Firebase C2 to intercept SMS, exfiltrate credentials (ATM PINs, card data, Aadhaar), and remotely control calls/USSD—demonstrating high technical sophistication and persistence.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.