New Android Banking Malware ‘DeVixor’ Adds Ransomware Capabilities
ID: 62075ee9-2b63-5038-a32d-5417e696ee06
STIX ID: report--62075ee9-2b63-5038-a32d-5417e696ee06
Feed Name: The Cyber Express
Threat Score
Cyble researchers detail deVixor, an evolving Android banking RAT targeting Iranian users via phishing APKs that combines credential theft, banking overlays, keylogging, notification harvesting, persistence and a remotely-triggered ransomware module; it uses Firebase and a Telegram bot infrastructure for scalable C2 and administration and has been observed across 700+ samples, indicating an active, maintained criminal service.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
