logo

Unmasking the SMS Stealer: Targeting Several Countries with Deceptive Apps

ID: 5e9b9d34-e346-5fbe-8665-a60919ea6bf8

STIX ID: report--5e9b9d34-e346-5fbe-8665-a60919ea6bf8

Feed Name: Zimperium Blog

Threat Score
78/100

Date Published: 2024-07-31

Date Updated: 2026-05-01

...
...

**Executive summary:** This report describes a large, evolving Android SMS-stealer campaign that infects devices via malicious ads and Telegram-distributed APKs, requests SMS read permissions to harvest OTPs, exfiltrates messages to C2 servers (initially via Firebase, later via GitHub-hosted JSON or embedded addresses), and appears monetized through services like fastsms.su; researchers identified ~107,000 samples, activity across 113 countries, ~2,600 Telegram bots, and 13 C2 servers, and published MITRE ATT&CK mappings and an IOC repository.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.