logo

New RecruitRat, SaferRat, Astrinox, Massiv Android Malware Found Targeting 800 Apps

ID: bfbde720-8a34-58cb-bd22-5013eb6b5be2

STIX ID: report--bfbde720-8a34-58cb-bd22-5013eb6b5be2

Feed Name: HackRead

Threat Score
78/100

Date Published: 2026-04-17

Date Updated: 2026-04-22

Author: Deeba Ahmed

...
...

Zimperium zLabs reports four active Android malware families—RecruitRat, SaferRat, Astrinox, and Massiv—used in distinct phishing and smishing campaigns to target banking and cryptocurrency apps. These families employ overlay attacks, Accessibility Service abuse, SMS interception, keylogging, MediaProjection screen recording, and persistent WebSocket channels to capture credentials, OTPs, and other sensitive data, with RecruitRat storing hundreds of fake login pages to trigger when targeted apps are opened.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.