New Malware Campaign Targets Russia: Key Threats And Protection Tips
ID: cd678292-defb-53ca-be79-729e0a29b006
STIX ID: report--cd678292-defb-53ca-be79-729e0a29b006
Feed Name: Cyble Blog
Cyble Research Labs identified an Android malware campaign dubbed “Falcon” that impersonates the VTB banking app to target Russian users. The app hides its icon, requests Accessibility permissions, and supports injection modules downloaded from a C2 (https://vtbsu.club/sweden/api/api.php?get_lend=) to target installed apps. Falcon can intercept and exfiltrate SMS and notifications, harvest contacts and device metadata, send spam, and perform USSD-based financial fraud; the report includes multiple IOCs (MD5/SHA1/SHA256 hashes and the C2 URL) and mitigation guidance such as using official app stores, enabling Play Protect, and performing factory resets if infected.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
