logo

Cloud Phones: The Invisible Threat

ID: 85b3848a-d929-5a80-a249-d809ee507483

STIX ID: report--85b3848a-d929-5a80-a249-d809ee507483

Feed Name: Group-IB Blog

Threat Score
75/100

Date Published: 2026-03-25

Date Updated: 2026-06-04

...
...

Cloud phones — remotely hosted Android instances and virtual/mobile environments — have evolved from social-media automation tools into an enabler for large-scale financial fraud: attackers create and sell pre-verified “dropper” accounts and e-wallets on darknet markets that retain consistent device telemetry, bypassing device-fingerprint defenses and facilitating ATO and APP scams; Group-IB documents detection challenges, active marketplace activity, regional loss estimates, and recommends multi-layered behavioral, network, and graph-based detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.