logo

Download a banker to track your parcel

ID: 4e3d13c7-7efd-5e04-a131-5e018e4d3702

STIX ID: report--4e3d13c7-7efd-5e04-a131-5e018e4d3702

Feed Name: Securelist by Kaspersky

Threat Score
75/100

Date Published: 2024-12-17

Date Updated: 2026-04-29

Author: Dmitry Kalinin

...
...

Kaspersky researchers uncovered a campaign distributing the Mamont Android banking Trojan through convincing fake wholesale/parcel-tracking websites and Telegram storefronts that lure victims into installing a ‘tracker’ app; the malware requests background, SMS, call and notification permissions, sends device info and a tracking number to a C2 (apisys003.com), and supports remote commands to intercept notifications, send SMS/USSD, hide/change icons, and present credential-harvesting overlays. The report includes technical details of the command set, the attackers’ social-engineering distribution technique, indicators of compromise (C2 domain and MD5), and telemetry showing over 31,000 blocked attacks in October–November 2024.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.