logo

Android Banker malware goes social

ID: 51b6d509-357f-57c3-bd93-cc690d3962d7

STIX ID: report--51b6d509-357f-57c3-bd93-cc690d3962d7

Feed Name: Zscaler Security Research Blog

Threat Score
75/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

Researchers discovered an Android banking Trojan masquerading as the Sberbank app that overlays legitimate apps to phish credentials, intercepts and exfiltrates SMS and call metadata, can send/place messages and calls via C2 commands, and uses device-administrator privileges and broadcast receivers to resist removal; targeted apps are configurable by the C2 and the malware displays fake login pages before showing a technical error to victims.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.