Nexus: New Android Banking Trojan Linked To SOVA
ID: a758865b-4260-5047-9878-2bce6f13741a
STIX ID: report--a758865b-4260-5047-9878-2bce6f13741a
Feed Name: Cyble Blog
The Nexus Android banking trojan—advertised on a Russian cybercrime forum and distributed via YouTube Vanced phishing pages—is a rebranded S.O.V.A variant that abuses Android Accessibility to steal banking credentials, SMS/2FA, and crypto wallet seed phrases, performs HTML-injection phishing in WebView for ~40 targeted banking apps, includes a ransomware module, and communicates with a C2 server (http://5.161.97.57:5000); the report includes technical analysis, IOCs, commands, and defensive recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
