logo

Android Banking Malware deVixor Actively Targeting Users with Ransomware Capabilities.

ID: 8be098d8-40f6-5be9-a4e3-59d61ea8c44f

STIX ID: report--8be098d8-40f6-5be9-a4e3-59d61ea8c44f

Feed Name: GBHackers

Threat Score
80/100

Date Published: 2026-01-13

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

deVixor is an actively maintained Android banking trojan and remote access tool observed since October 2025 that combines SMS and credential theft, WebView-injection overlays, keylogging, extensive use of Android Accessibility Service, and a remotely triggered ransomware lock (configured via LockTouch.json). The campaign spreads via counterfeit automotive websites delivering malicious APKs, uses Telegram and Firebase for command-and-control and operator administration, and targets Iranian financial institutions and cryptocurrency exchanges; researchers analyzed over 700 samples and identified domain-based IOCs and Telegram channels evidencing large-scale, sophisticated operations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.