Unmasking the SMS Stealer: Targeting Several Countries with Deceptive Apps
ID: 5e9b9d34-e346-5fbe-8665-a60919ea6bf8
STIX ID: report--5e9b9d34-e346-5fbe-8665-a60919ea6bf8
Feed Name: Zimperium Blog
**Executive summary:** This report describes a large, evolving Android SMS-stealer campaign that infects devices via malicious ads and Telegram-distributed APKs, requests SMS read permissions to harvest OTPs, exfiltrates messages to C2 servers (initially via Firebase, later via GitHub-hosted JSON or embedded addresses), and appears monetized through services like fastsms.su; researchers identified ~107,000 samples, activity across 113 countries, ~2,600 Telegram bots, and 13 C2 servers, and published MITRE ATT&CK mappings and an IOC repository.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
