logo

Spy, Steal, Lock: deVixor Android Trojan Hits Banking & Crypto Users

ID: 86c12efa-5083-5344-8a8b-c79807282a82

STIX ID: report--86c12efa-5083-5344-8a8b-c79807282a82

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-01-14

Date Updated: 2026-04-23

Author: Ddos

...
...

deVixor is a modular Android banking trojan actively targeting Iranian users since October 2025. Initially an SMS harvester, it now performs WebView-based credential theft, keylogging, media exfiltration, OTP and account data harvesting, and includes a remotely triggered ransomware module; attackers distribute it via phishing sites hosting malicious APKs and use Telegram for C2.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.