logo

Android OS-Level Attack Bypasses Mobile Payment Security

ID: 83ae548f-82f9-5f53-9f94-c88dad0d874d

STIX ID: report--83ae548f-82f9-5f53-9f94-c88dad0d874d

Feed Name: Infosecurity Magazine (News)

Threat Score
75/100

Date Published: 2026-03-17

Date Updated: 2026-04-22

...
...

CloudSEK researchers identified a new Android attack technique that uses the LSPosed framework and a module dubbed "Digital Lutera" to inject system-level hooks that intercept SMS messages, spoof device identifiers, and extract 2FA in real time, enabling large-scale payment fraud and account takeovers while bypassing app signatures and protections like Google Play Protect; activity has been observed being coordinated on Telegram and the method undermines SIM-binding and device-reported signals used by banks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.