SMS Stealer Phishing Campaign Hits Indonesia's BRI Bank
ID: 94a0347a-9dba-52dd-a6ab-e099a17a14ee
STIX ID: report--94a0347a-9dba-52dd-a6ab-e099a17a14ee
Feed Name: Cyble Blog
Threat Score
This report documents a phishing campaign targeting Bank Rakyat Indonesia (BRI) in which threat actors distribute Android SMS-stealer malware (a custom 'Brimo' sample and an SmsEye-based sample) via malicious APKs to harvest banking credentials and automatically exfiltrate OTPs to bypass 2FA; the analysis includes APK metadata, manifest and source-code observations, C2/Telegram exfiltration details, hashes and phishing URLs, MITRE ATT&CK mappings, and recommended mitigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
