logo

Malicious Android Apps Pose as Google, Instagram, WhatsApp to Steal Credentials

ID: 7de91bde-dd7c-5570-9256-b2dd3cdaab80

STIX ID: report--7de91bde-dd7c-5570-9256-b2dd3cdaab80

Feed Name: The Hacker News

Threat Score
75/100

Date Published: 2024-05-10

Date Updated: 2026-05-05

Author: [email protected] (The Hacker News)

...
...

Malicious Android apps posing as well-known services (Google, Instagram, WhatsApp, X, etc.) are being distributed via social engineering (including WhatsApp lures and smishing/TOAD) to trick users into granting accessibility and device-administrator permissions; once installed they connect to C2 servers to harvest contacts, SMS, call logs, installed apps, send SMS, open phishing overlays mimicking major services, and facilitate banking fraud. The report references multiple Android malware families (Coper, Vultr, Tambir, Dwphon), notes Google Play Protect blocks known variants, and telemetry indicating a 32% year-over-year increase in mobile banking trojan victims (75,521), concentrated in Turkey, Saudi Arabia, Spain, Switzerland, and India.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.