Download a banker to track your parcel
ID: 4e3d13c7-7efd-5e04-a131-5e018e4d3702
STIX ID: report--4e3d13c7-7efd-5e04-a131-5e018e4d3702
Feed Name: Securelist by Kaspersky
Kaspersky researchers uncovered a campaign distributing the Mamont Android banking Trojan through convincing fake wholesale/parcel-tracking websites and Telegram storefronts that lure victims into installing a ‘tracker’ app; the malware requests background, SMS, call and notification permissions, sends device info and a tracking number to a C2 (apisys003.com), and supports remote commands to intercept notifications, send SMS/USSD, hide/change icons, and present credential-harvesting overlays. The report includes technical details of the command set, the attackers’ social-engineering distribution technique, indicators of compromise (C2 domain and MD5), and telemetry showing over 31,000 blocked attacks in October–November 2024.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
