logo

Banking Trojan Targets Banking Users in Malaysia

ID: 14c851b9-8bbf-5948-a59d-7bb2ab336404

STIX ID: report--14c851b9-8bbf-5948-a59d-7bb2ab336404

Feed Name: Cyble Blog

Threat Score
70/100

Date Published: 2025-05-20

Date Updated: 2026-07-16

...
...

This report analyzes an Android banking Trojan that impersonates a Malaysian cleaning-service app and website to steal SMS messages and internet-banking credentials; it includes technical artifacts (package name, SHA256), manifest/permission abuse (RECEIVE_SMS), source/traffic observations showing SMS and credential exfiltration to C2 domains, hosted phishing pages for multiple Malaysian banks, MITRE ATT&CK mappings, and IOCs (malicious APK hash and C2 URLs).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.