Frogblight Malware Targets Android Users With Fake Court and Aid Apps
ID: e96e9bb2-35bb-5931-a5b9-a0d8f8e5e2e5
STIX ID: report--e96e9bb2-35bb-5931-a5b9-a0d8f8e5e2e5
Feed Name: HackRead
Kaspersky Securelist uncovered Frogblight, a rapidly evolving Android banking Trojan targeting users in Turkiye via smishing and fake court or social-aid apps (e.g., e-ifade.apk, 'Davalarım'). After obtaining extensive permissions the malicious app opens legitimate government sites and injects hidden JavaScript to capture banking credentials, and newer variants add keylogging, contact and call-log theft, and anti-analysis/geo-based shutdowns; researchers link the infrastructure and source code to possible malware-as-a-service.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
