logo

Rapid Response: Zimperium Detects Lazarus Stealer Campaign with Full Coverage and Additional Samples

ID: b22086cf-aa6f-5f3a-82bc-6e4b13f2aced

STIX ID: report--b22086cf-aa6f-5f3a-82bc-6e4b13f2aced

Feed Name: Zimperium Blog

Threat Score
75/100

Date Published: 2025-08-20

Date Updated: 2026-05-01

...
...

Lazarus Stealer is an Android banking trojan masquerading as a legitimate utility (GiftFlipSoft) that hides from the user interface, abuses intrusive permissions (SMS default role, overlay, usage access) to intercept OTPs and monitor apps, dynamically loads phishing overlays via WebView, and persistently exfiltrates credentials to C2 servers; the report identifies 46 related samples and publishes IOCs while noting detection by mobile security products.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.