logo

No need to RSVP: a closer look at the Tria stealer campaign

ID: 885da91c-2edc-51e6-878c-52083b7b410a

STIX ID: report--885da91c-2edc-51e6-878c-52083b7b410a

Feed Name: Securelist by Kaspersky

Threat Score
72/100

Date Published: 2025-01-30

Date Updated: 2026-04-29

Author: Fareed Radzi

...
...

Tria Stealer is an active Android infostealer campaign (mid‑2024 onward) targeting users in Malaysia and Brunei with wedding‑invitation lures; the APK requests SMS/notification permissions, captures SMS, calls, messaging and email content, and exfiltrates data to Telegram bots to enable WhatsApp/Telegram account takeover and financial fraud. The report includes technical details, attack flow, analyzed APK behaviors and a list of Telegram bot tokens and related IOCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.