Fake App Attack Targets Japanese Telecom Users
ID: e2715cec-43db-59fc-bc52-718e1e7574b4
STIX ID: report--e2715cec-43db-59fc-bc52-718e1e7574b4
Feed Name: Cyble Blog
Cyble Research Labs analyzed an Android malware campaign that impersonates a major Japanese telecom app to phish users for their network PINs and credentials by loading the legitimate payment site in a WebView, injecting JavaScript to scrape credentials, capturing session cookies via the Cookie Manager API, and exfiltrating stolen data to the attacker via SMTP; the researchers recovered 2,900+ stolen credentials/cookies from the attacker's infrastructure and documented APK metadata, obfuscation/decryption routines, and IOCs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
