Android malware, Android malware and more Android malware
ID: 93e64f92-87b0-5a52-b1dd-7d1594066f3d
STIX ID: report--93e64f92-87b0-5a52-b1dd-7d1594066f3d
Feed Name: Securelist by Kaspersky
This report summarizes Kaspersky private crimeware findings on Android threats in 2023, describing three Android malware families: Tambir (Turkish-targeting backdoor/spyware using accessibility abuse and C2 retrieval via public channels), Dwphon (preinstalled-like component possibly introduced via supply-chain affecting OEM devices and collecting system/app data), and Gigabud (Kotlin-based RAT targeting banking users with credential theft, screen streaming, and accessibility-based 2FA bypass). The report includes capabilities, observed telemetry, and multiple sample hashes as indicators of compromise, and recommends avoiding unofficial app stores and monitoring app permissions.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
