No need to RSVP: a closer look at the Tria stealer campaign
ID: 885da91c-2edc-51e6-878c-52083b7b410a
STIX ID: report--885da91c-2edc-51e6-878c-52083b7b410a
Feed Name: Securelist by Kaspersky
Threat Score
Tria Stealer is an active Android infostealer campaign (mid‑2024 onward) targeting users in Malaysia and Brunei with wedding‑invitation lures; the APK requests SMS/notification permissions, captures SMS, calls, messaging and email content, and exfiltrates data to Telegram bots to enable WhatsApp/Telegram account takeover and financial fraud. The report includes technical details, attack flow, analyzed APK behaviors and a list of Telegram bot tokens and related IOCs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
