logo

Fake App Attack Targets Japanese Telecom Users

ID: e2715cec-43db-59fc-bc52-718e1e7574b4

STIX ID: report--e2715cec-43db-59fc-bc52-718e1e7574b4

Feed Name: Cyble Blog

Threat Score
70/100

Date Published: 2025-12-09

Date Updated: 2026-07-16

...
...

Cyble Research Labs analyzed an Android malware campaign that impersonates a major Japanese telecom app to phish users for their network PINs and credentials by loading the legitimate payment site in a WebView, injecting JavaScript to scrape credentials, capturing session cookies via the Cookie Manager API, and exfiltrating stolen data to the attacker via SMTP; the researchers recovered 2,900+ stolen credentials/cookies from the attacker's infrastructure and documented APK metadata, obfuscation/decryption routines, and IOCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.