logo

Uzbek Users Under Attack by Android SMS-Stealers

ID: 51bafb71-18b9-5c7c-ab15-1ad66a41a789

STIX ID: report--51bafb71-18b9-5c7c-ab15-1ad66a41a789

Feed Name: Dark Reading

Threat Score
70/100

Date Published: 2025-12-22

Date Updated: 2026-04-21

Author: Alexander Culafi

...
...

Group-IB observed a new wave of Android-focused malware attacks in Uzbekistan beginning in October, where multiple threat actors (including TrickyWonders, Blazefang, and Ajina) distribute malicious APKs via sideloading and compromised Telegram accounts to deploy SMS stealers and banking trojans (e.g., Wonderland, Ajina.Banker, Qwizzserial). Attackers use droppers (MidnightDat, RoundRift), strong obfuscation, fake uninstall prompts, and frequent changes to domains/package names to evade detection, enabling repeated fund withdrawals and rapid propagation through victims' contact lists; defenders are advised to monitor user sessions, use threat intelligence, and factory-reset infected devices.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.