logo

Iranian Mobile Banking Malware Campaign Threat Continues

ID: 07a6a419-587b-5a00-bf84-fa19dfe9583c

STIX ID: report--07a6a419-587b-5a00-bf84-fa19dfe9583c

Feed Name: Zimperium Blog

Threat Score
72/100

Date Published: 2023-11-28

Date Updated: 2026-05-01

...
...

Zimperium uncovered 245 new variants of an Iranian mobile banking malware campaign (28 of which were undetected) that harvests banking credentials, credit card data, and OTPs via accessibility-service overlays and phishing webviews; operators use GitHub and intermediate C2s to distribute active phishing URLs and exfiltrate stolen data to Telegram channels, with vendor-specific evasion for Xiaomi/Samsung and potential expansion to crypto wallets and iOS.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.