Malicious Android Apps Pose as Google, Instagram, WhatsApp to Steal Credentials
ID: 7de91bde-dd7c-5570-9256-b2dd3cdaab80
STIX ID: report--7de91bde-dd7c-5570-9256-b2dd3cdaab80
Feed Name: The Hacker News
Malicious Android apps posing as well-known services (Google, Instagram, WhatsApp, X, etc.) are being distributed via social engineering (including WhatsApp lures and smishing/TOAD) to trick users into granting accessibility and device-administrator permissions; once installed they connect to C2 servers to harvest contacts, SMS, call logs, installed apps, send SMS, open phishing overlays mimicking major services, and facilitate banking fraud. The report references multiple Android malware families (Coper, Vultr, Tambir, Dwphon), notes Google Play Protect blocks known variants, and telemetry indicating a 32% year-over-year increase in mobile banking trojan victims (75,521), concentrated in Turkey, Saudi Arabia, Spain, Switzerland, and India.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
