Android Banking Trojan Spreads via WhatsApp Using Fake KYC Lures
ID: 4430fc2c-7a64-5d69-9281-73811ec287ba
STIX ID: report--4430fc2c-7a64-5d69-9281-73811ec287ba
Feed Name: Cyber Press
Threat Score
An active Android banking trojan circulated via WhatsApp masquerades as a mandatory "Banking KYC" app to phish Indian users; it employs a two-stage dropper, native-code obfuscation, hidden secondary payload, a local full-tunnel VPN and Firebase C2 to intercept SMS, exfiltrate credentials (ATM PINs, card data, Aadhaar), and remotely control calls/USSD—demonstrating high technical sophistication and persistence.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
