logo

New Android Banking Malware ‘DeVixor’ Adds Ransomware Capabilities

ID: 62075ee9-2b63-5038-a32d-5417e696ee06

STIX ID: report--62075ee9-2b63-5038-a32d-5417e696ee06

Feed Name: The Cyber Express

Threat Score
75/100

Date Published: 2026-01-13

Date Updated: 2026-04-23

Author: Paul Shread

...
...

Cyble researchers detail deVixor, an evolving Android banking RAT targeting Iranian users via phishing APKs that combines credential theft, banking overlays, keylogging, notification harvesting, persistence and a remotely-triggered ransomware module; it uses Firebase and a Telegram bot infrastructure for scalable C2 and administration and has been observed across 700+ samples, indicating an active, maintained criminal service.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.