Dynamically Evolving SMS Stealer Threatens Global Android Users
ID: e663a611-21a1-5279-aade-983902057bb5
STIX ID: report--e663a611-21a1-5279-aade-983902057bb5
Feed Name: Dark Reading
Date Published: 2024-07-31
Date Updated: 2026-04-21
Author: Elizabeth Montalbano, Contributing Writer
Researchers tracked a large, evolving Android malware campaign called "SMS Stealer" that has produced over 107,000 samples and infected users in 113 countries by distributing dynamically generated malicious apps via Telegram bots and deceptive ads. The trojan requests SMS permissions after sideloading, connects to multiple command-and-control servers (at least 13) and exfiltrates SMS messages—primarily OTPs—for account takeover, credential theft, and further fraud; the campaign uses ~2,600 Telegram bots and targets users of over 60 major brands, evading signature-based defenses and highlighting the need for stronger mobile threat protection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
