logo

Android Banking Trojan & SMS Stealer Floating In The Wild

ID: 687dfe2f-c097-50af-9015-4599e24a3c5e

STIX ID: report--687dfe2f-c097-50af-9015-4599e24a3c5e

Feed Name: Zscaler Security Research Blog

Threat Score
70/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

This report analyzes an Android banking Trojan (888.apk) targeting Chinese mobile users that intercepts SMS and calls, harvests contacts and banking-related messages, and exfiltrates data via e-mail, SMS, and web requests; the sample has low antivirus detection and includes IoCs (MD5 ff081c1400a948f2bcc4952fed2c818b, distribution URL, and a hardcoded Chinese phone number) plus screenshots of captured data and control commands.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.