SikkahBot Malware Campaign Defrauds Students In Bangladesh
ID: d6aeba36-66b0-5e85-90ec-9428397edeca
STIX ID: report--d6aeba36-66b0-5e85-90ec-9428397edeca
Feed Name: Cyble Blog
**Executive Summary:** Cyble Research and Intelligence Labs uncovered SikkahBot, an Android banking malware active since July 2024 that impersonates the Bangladesh Education Board to lure students via smishing and shortened links; once installed it harvests personal and payment data, intercepts bank-related SMS, abuses the Accessibility Service to autofill credentials for bKash/Nagad/DBBL, and performs automated USSD transactions, with multiple variants and low VirusTotal detection indicating ongoing active development.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
