logo

Malware Campaign Targeting Opera Mobile

ID: 71459285-cd1d-55b3-a8ef-fbb2e1832f5c

STIX ID: report--71459285-cd1d-55b3-a8ef-fbb2e1832f5c

Feed Name: Zscaler Security Research Blog

Threat Score
65/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

Malicious pages on newly-registered domains (e.g., geqe.net and mskmarkets.ru) impersonate Opera Mobile to trick WAP-enabled users—particularly in Russia/Eastern Europe—into downloading a Java application called browser_update.jar that is identified as SMS-sending malware by multiple AV engines; the report includes sample URLs, behavioral notes, and contextual risk guidance for mobile users.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.