DeVixor Android Banking RAT Targeting Iran
ID: 9e16e3a0-4ccb-5b47-85dc-426b11dc1e17
STIX ID: report--9e16e3a0-4ccb-5b47-85dc-426b11dc1e17
Feed Name: Cyble Blog
deVixor is an actively developed Android banking RAT distributed via phishing websites posing as automotive businesses and targeting Iranian users; CRIL analysis of 700+ samples shows it harvests SMS-based financial data (OTPs, balances, card numbers), injects JavaScript into WebView for credential theft, performs keylogging and device surveillance, resists detection via Play Protect bypasses and Accessibility abuse, and supports a remotely-triggerable ransomware module — managed at scale via Firebase and Telegram-based C2.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
