logo

Android Banking Trojan Linked to Cambodia Scam Compounds Hits 21 Countries

ID: aaf770c3-9ca0-5d32-88a8-951464e7af1f

STIX ID: report--aaf770c3-9ca0-5d32-88a8-951464e7af1f

Feed Name: HackRead

Threat Score
75/100

Date Published: 2026-04-10

Date Updated: 2026-04-22

Author: Waqas

...
...

**Executive Summary:** Infoblox Threat Intel (with Chong Lua Dao) links a Southeast Asian forced‑labour scam compound in Cambodia to an Android banking trojan used across 21 countries; attackers deploy dozens of fake domains to distribute malicious sideloaded apps, operate a malware‑as‑a‑service model, and use trafficked workers to run distribution and social engineering, while the trojan intercepts SMS, bypasses biometric checks, overlays banking apps, and enables real‑time fraudulent transactions—reportedly affecting victims in Southeast Asia, Europe, and Latin America and including technical IOCs and mitigation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.