logo

SMS Stealer Phishing Campaign Hits Indonesia's BRI Bank

ID: 94a0347a-9dba-52dd-a6ab-e099a17a14ee

STIX ID: report--94a0347a-9dba-52dd-a6ab-e099a17a14ee

Feed Name: Cyble Blog

Threat Score
70/100

Date Published: 2026-03-18

Date Updated: 2026-07-17

...
...

This report documents a phishing campaign targeting Bank Rakyat Indonesia (BRI) in which threat actors distribute Android SMS-stealer malware (a custom 'Brimo' sample and an SmsEye-based sample) via malicious APKs to harvest banking credentials and automatically exfiltrate OTPs to bypass 2FA; the analysis includes APK metadata, manifest and source-code observations, C2/Telegram exfiltration details, hashes and phishing URLs, MITRE ATT&CK mappings, and recommended mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.