logo

Widespread OTP-Stealing Campaign Targets Android Users

ID: bc7d9ace-e307-5762-89c7-40c5f86d329f

STIX ID: report--bc7d9ace-e307-5762-89c7-40c5f86d329f

Feed Name: Security Boulevard

Threat Score
78/100

Date Published: 2024-08-01

Date Updated: 2026-04-22

Author: Jeffrey Burt

...
...

Zimperium zLabs uncovered a sophisticated Android malware campaign dubbed "SMS Stealer" that uses malicious apps, fake ads, and thousands of Telegram bots to trick victims into granting SMS access; once installed the malware connects to C2 servers to exfiltrate incoming texts (notably OTPs), enabling account takeovers, fraud, and escalation to ransomware across more than 113 countries and hundreds of targeted brands.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.