Zscaler Protections Against Flubot Banking Malware
ID: dff4d2a9-a586-5e1c-af8a-77f554e01767
STIX ID: report--dff4d2a9-a586-5e1c-af8a-77f554e01767
Feed Name: Zscaler Security Research Blog
This report describes the widespread Flubot Android banking malware campaign that uses SMS-based smishing to trick users into installing fake delivery or Chrome apps; once installed it harvests SMS and contacts, uses Accessibility Services to disable protections and display fake overlays to steal banking credentials and credit-card data, spreads via the victim's contacts, and uses DGA/RSA-protected C2 communications; the report also references vendor analysis and Zscaler detection coverage.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
