Iranian Mobile Banking Malware Campaign Threat Continues
ID: 07a6a419-587b-5a00-bf84-fa19dfe9583c
STIX ID: report--07a6a419-587b-5a00-bf84-fa19dfe9583c
Feed Name: Zimperium Blog
Threat Score
Zimperium uncovered 245 new variants of an Iranian mobile banking malware campaign (28 of which were undetected) that harvests banking credentials, credit card data, and OTPs via accessibility-service overlays and phishing webviews; operators use GitHub and intermediate C2s to distribute active phishing URLs and exfiltrate stolen data to Telegram channels, with vendor-specific evasion for Xiaomi/Samsung and potential expansion to crypto wallets and iOS.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
