logo

DeVixor Android Banking RAT Targeting Iran

ID: 9e16e3a0-4ccb-5b47-85dc-426b11dc1e17

STIX ID: report--9e16e3a0-4ccb-5b47-85dc-426b11dc1e17

Feed Name: Cyble Blog

Threat Score
78/100

Date Published: 2026-01-19

Date Updated: 2026-07-16

...
...

deVixor is an actively developed Android banking RAT distributed via phishing websites posing as automotive businesses and targeting Iranian users; CRIL analysis of 700+ samples shows it harvests SMS-based financial data (OTPs, balances, card numbers), injects JavaScript into WebView for credential theft, performs keylogging and device surveillance, resists detection via Play Protect bypasses and Accessibility abuse, and supports a remotely-triggerable ransomware module — managed at scale via Firebase and Telegram-based C2.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.