Android Phones Pre-Downloaded With Malware Target User Crypto Wallets
ID: 778713d5-0a79-54ac-ac14-ae5b82b013f4
STIX ID: report--778713d5-0a79-54ac-ac14-ae5b82b013f4
Feed Name: Dark Reading
Date Published: 2025-04-17
Date Updated: 2026-05-05
Author: Kristina Beek, Associate Editor, Dark Reading
Research from Doctor Web and other vendors found cheap, counterfeit or imitation Android phones preloaded with Trojanized WhatsApp/Telegram apps (using an LSPatch injector called Shibai) and other malware (e.g., Triada) that steal cryptocurrency via clipboard address replacement, harvest messages and files, and exfiltrate device data; the campaign leverages supply-chain compromise, operates dozens of C2 servers and domains, and has funneled significant sums into attacker-controlled wallets.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
