logo

Android malware, Android malware and more Android malware

ID: 93e64f92-87b0-5a52-b1dd-7d1594066f3d

STIX ID: report--93e64f92-87b0-5a52-b1dd-7d1594066f3d

Feed Name: Securelist by Kaspersky

Threat Score
75/100

Date Published: 2024-03-20

Date Updated: 2026-04-29

Author: GReAT

...
...

This report summarizes Kaspersky private crimeware findings on Android threats in 2023, describing three Android malware families: Tambir (Turkish-targeting backdoor/spyware using accessibility abuse and C2 retrieval via public channels), Dwphon (preinstalled-like component possibly introduced via supply-chain affecting OEM devices and collecting system/app data), and Gigabud (Kotlin-based RAT targeting banking users with credential theft, screen streaming, and accessibility-based 2FA bypass). The report includes capabilities, observed telemetry, and multiple sample hashes as indicators of compromise, and recommends avoiding unofficial app stores and monitoring app permissions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.