logo

Massive SMS stealer campaign infects Android devices in 113 countries

ID: 7e47e9d7-1825-5b7c-a5ec-fcaace14c1cc

STIX ID: report--7e47e9d7-1825-5b7c-a5ec-fcaace14c1cc

Feed Name: Bleeping Computer

Threat Score
78/100

Date Published: 2024-07-30

Date Updated: 2026-07-17

Author: Bill Toulas

...
...

Zimperium researchers uncovered a global Android malware campaign (tracked since Feb 2022) that uses ~2,600 Telegram bots and malvertising to distribute SMS-stealing APKs — over 107,000 distinct samples were observed. The malware exfiltrates OTPs/SMS to an API at fastsms.su, enabling attackers or a service to monetize infected devices as virtual phone numbers for authentication and anonymization, primarily impacting users in India and Russia with notable victims in Brazil, Mexico, and the U.S.; users are advised to avoid sideloading APKs and restrict SMS permissions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.