logo

Fake Bahrain Government Android App Steals Personal Data Used for Financial Fraud

ID: fedfaad4-c9b7-550e-8418-06e9be2df3f7

STIX ID: report--fedfaad4-c9b7-550e-8418-06e9be2df3f7

Feed Name: McAfee Labs Blog

Threat Score
65/100

Date Published: 2024-05-31

Date Updated: 2026-04-28

Author: McAfee Labs

...
...

**Executive summary:** McAfee Mobile Research identified an Android InfoStealer campaign targeting users in Bahrain by impersonating the Labour Market Regulatory Authority and various financial/loan apps to collect CPR numbers, phone numbers, personal data and SMS; distribution occurs via fake Facebook pages and SMS phishing and the malware uses Firebase Firestore for dynamic phishing URL loading. The report provides multiple IOCs (SHA256 hashes, package names, malicious domains and Firebase endpoints) and notes roughly 62 observed victims at the time of writing.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.