Discovery of Qwizzserial: A New Android SMS Stealer Family
· Published 04/07/2025 10:12 · Modified 04/07/2025 10:49
Essential information
- Published
- 04/07/2025 10:12
- Modified
- 04/07/2025 10:49
- Tags
- 2025-07-04 financial fraud qwizzserial sms stealer
- Related entities
- 200 observables, 1 malware, 2 others
Description
A new Android SMS stealer family, named Qwizzserial, has been uncovered, primarily targeting users in Uzbekistan. The malware exploits the reliance on SMS for two-factor authentication in local payment systems, allowing fraudsters to intercept SMS messages and gain control over victims' finances. Distributed through Telegram, the Qwizzserial campaign mirrors the structure of Classiscam. The stealer has infected approximately 100,000 users, resulting in financial losses of at least US$62,000. The malware's effectiveness stems from the widespread use of SMS for various financial transactions in Uzbekistan, including P2P transfers, payments, and authorization confirmations, often serving as the sole security layer in the absence of 3D Secure or biometric authentication.
Related entities
Vulnerabilities, IOCs, intrusion sets, MITRE techniques and other entities referenced in this report.
Observables (200)
llkjllj.topffd78f19134e09072a8b2e6768907df4fdb83ce6cfdf0c31485316980f09a0e7ffac9edf6e51f0c723c7e86e2e12c879fae13ac606d19e6ed0e46840c975991cff448941c3abd2cda580e4442fffded7ab427936c279ff84c292a83300303a53ff1d862acccc2a49b780bb4cbab8a543ee985e07ebe5af283b90f58277869b5bfeaf6e5fc0bc9aae6b4255db37738f87f9d10c4709bbefbc21339773a73463d9fe7c97ef54e9f416d6de71daec72e529232aec0c8783e756c0b1cc333601116cfe438ef2f8ef7d3569689b643054ad2691822ae9c593e2707e5b012918f51495fe391e82fea4d7fb71c3b68a2a137675b6f85f92f9041c441b88a4b6dbd1974afe3443ffbdee2c8981f998fa08a9e3ae402be84776dbe3a97159871c142ec3fbfdd842ac6a75b4d826208ce556ef6012a5f8846aec756ccabb179956e684c75bfd854355401524c44ff6b381771f9ba1f5f17f1155e400dfe8f1211ee66fbf3efd4a191287520b749728a0b5b1ad2ff5a2d1866e19d958771bb3ea2ec4ab230cfcf2646eeec01ef6719fbf8d9f165f5bb7d42c1e2f37fc04862b71b833610117fcedad1b0a586e456e7e2dc08175d67485dedc6aa5cd5052e25c76e1ba072006fc9ff3fec4c7aca37dc5a7a647295272900b8d0c6b9dec5e6ae1f7a155cf0209fc4ec9400016c73553b229e9d6f1166d7cc84c872dce5a2b32037eca803236fbfc199b9156e67a6ec7a60744041d6f290083c2da64bfe903e2b6ec53c182d44cfbefe9ee9634ed37522d8694e5d3c683ceb67c305fd8e6a6077bad65c66e8f0bfb533979023f9be4caf6dbdacf11b80d5191e9bb41f744f6de1026f899f414e5fafda8e9be4a48693481983a9196b463c5182dd3e50960ac02309823d1cabbeffaffb2e6524ef2c136f7f1adb4d134824a35466e705a9084219777d439c439fcfa72d264f24fe57c9fff51ee5990526e600178e61777a2266562ca7a4d7f469ffa6cf0ed8a4bbb6fc30457487c46388baeb074251796bca7f20665664e4f8c7afa4b7f10a8263886dc728ec649f6e13d21a412b659a82022158ddecaff06e3d8f9b84e58e74493e82a703eb539e05ce53220658360090a1cdc8fa214d6c256f2f89502a04200112651b3c934441bf03066cf0f5f4e98cb753ef7114c95ba0c53f88e85bd6e02c6f4b3b68f36f4a7ffedc1b4bb61f2ac5417ea1b25de7c78a3caf86e07133092555466c6d11a8af64dcae1fba4d920b13df83b8549c976139babf86dfd09499fc13b710c6ae1baa08aa91029e5d26ae9184d24b622f0c0d93f37f86dc55feffe0d971b59c569e6df570a7c3fe7462e8f6f368e972e74d1d08d7cf7f257086e74c482e3c33c8cfbe3de0f22f126646fdb51c765aa64d03a09350cf77f4814438cd4cb1e43c8a12245fb625839d420f402c48609136c51b1199924f7f146de7f066b30b9af42d07198b36ec49aafab8e1b1a60e440ba520622609df756fc6b2b99e2ddeebc1f0309fd204291f5ed6f2fbe1789b6af142a4fc77cecf6c899abaeb4478d124b9ff213ee05426815616b829770d200e1101a50c1374bf737c03ec9eae9d10f750c9c2235629a99891a4a984b4c994904c9c131d0c5d1f69e985ecd51a0aa2c55f3b4fa0379901ebf415c3e5357de9498d1c55a0f7eaaf63664e06ffb0335e5e44d3bb2e4c2b60153837aa235bdd4a04fc904114f5ae4f64760003a553816a814a976a1ff0ca77691c53ff5a805c22ae117e45ef20fd4f668d9b4f897a437ad67ad3c654da7313a4152884ad0068ffe58cab6d51d6ac2f5f0a1d0003590e39f7e48003ddf0694e7f653744502d02d2c0776ee12afd3c5f5df979487a4726758c8783ae0556fdc9ccff7cf81882703d638abb8200c01fcf5794d0ee0a44fb263c697396af9e1f4a83b9ff74733ac8fa87dce0c1800d1fdf57523d2d379abeddb9d00b01b71abcdf844855e51346e2d3bba47ca2d9f89eef4a28c363e41627f6dc585da16382a062f7d0aef6bf00fed751f1e493c305197f57084f08d887231ddb1a8f648d4e53dda334e9328d755bbe1f77015148eb5dbf472de5164558b4819ee2af16fa7f187f10eef74b6dc126035b3d03e33fa1babf4478b1c4f86934721efdf915e4d5b6ac7e393d6cc5dbbb09ad47ee2db98f748f414659b99c65c61214a17bd0f041d62df2565fc0aea2ca7211b1507e1b3a187f3d7ca34f9cf70943ce3612d08a8445fd0540bb3dd7e703862ca2f7347aa3c49f39448362d11ec12e7f08b9bd8492d8215b9d8d082e0ba66d264a40f2b3587acf3812de450b6075cfda578de9313a895f2f65f6051f40b8c7e04954c447c2da7f2a2e2c81eabbe55b6ee5592d3f6c95232c3f9d3fadac8ab495beae4e93b093df29c55edca8939f1ef3ea4ea100f1597b75dd92ad238a47b2e4d4c18d2d41d8af28b0537ef08d132384c2ffe8c4eb3bb3fb3a0c4521ce1ab83c720a36b9e4654f256dffa7f15651f5d4d6e8f7cbb07126db86013e5c8032db4eed37d41593deff0a5882ec22908880d603b682fa0e89c543d0c4487f79ec4fb4ca2448e00f55df07563b324975e81d9a0aa16a8e460a8dfc49dabccebeb0d7643eb829514b016f06ec9e74c69ad77ded4d08af8e268f44858d1e8e004aeb837294c3bce799066f04f08aa8eac31a35b165976b0ffff20a91722ca4fd1cc7584f0d2a04e58284af000c0bb7a1d5b052d734b724b0c0d6c07247f426ea9571885c57cca18a181c7ef898bb281d4a033358c13e8ae4b8f6002ccabfc42d01498a256079741e1a50def4a3f6945c388aa59348538550726889e26f56f728af733d04d27828900e50bef48aaad2247c091df6fbd46d849e2296c9d933bf8ffb595f652a74d5c3da0ceef44dd64e6d47faa1a5897f92421989ccbbbcc2408ef761272b3a7327a0a2a83ef1a351ab77a0425a6a5b1c0551fbfb65a503790bd2488504d0115a698c99997eeda9f6b89b65db7821b3bd3c5f9cbd3b57d645a2218ae7051183fbedd7ea0f7eeadca5150746b2e5e07004d9cb59b3c37fc5aa9656b16223dc11f5d86cd9c5dee39f3ed2efaed9931a7cba8abcd3e14068c717412f6993ab7d98adca12a590fee301c286f106e211ab5069066523236229ccc405f2b08efcc60ea192aa7de5eedf66baf7c02a67cea6d81b78c0f31c4c4d354917294f07d79a4a7779c8ff7daedd198a9ef7bbb103da295d2eff64001738865341464d629701114b62684739fedbfdee3b229b03d0b5c4255fef83f3ad2aeb262dce2c8fa678d862c3cc2aef5ed4a2ec5a082c4edfb8f73294dba9e5d38d8e6e55741536f7e7744b12facbf52ed117e4bdda9f7e1c7f03191489283184c4474c54d662be5f7c23686afa1e080ed0768895ab57fb6ffd2b4104b414fe784482203d8cc01a0f840a0ce5a8a9993ecfa2e9874264ff10f443d8306353cde66a28c4194716ba2a3831a1f1fdd38c0ec9bac8e632228faa65bcb6a3a617d9d821fcfe2cadd51162bd2caf0dee82a7dec8c2f96d13e4410c60643591daf23ed6e9ea1b75e12a294bacba75cb9c7d51fec2acbe21c6da2c692983151cc64f5b03349f8861e85c437bfbb7c244ad01cafec0faac58b0f3a758e782e7c58e2f87bf7694b2403451a1c279a0bce53b5513bec065d0b5e27ff5ddaff3089a3719d27102037d00a55e0b0376c74dec0804b86ebf416ae068b34d9aab2bb96e188fbf997830317f1e9f460d9deb884aa43eff7ebed4a2b96ecaadccc3772beedba0b265a5741545cc708e33ab22acf2c6a6af2ebb75a1736630b10651ff113b16bbe39f6dfb7a4b046e765119d8069411924c9eb7c12c9652b0477fee19380d08ecf689609dbaa8030755a680c7698bfcf2857eb5565ade2cf59bad8d929d5e2d3a7eb8aaf00fd662787c94615d5a2a00c08d9eb3a011bc587b74bde89cacf92c85e319ccd04db81f69e08adcb6db40d6895c4eae70715ec4912e027acaeace274d00db7b84fd775efef14b34e24c2a1cfce2aeaacc50ac99056f1f34f954c482cf89f0cf4cc25cbdd6860f2c5cb39829ae1e7ea9e7080d97eda4f83c7e8c39f339bba7bb667caa7d3c638b5498ca547612f15ea8d698016aebea8c6656633ae3d3c484ed2ea05c590fa7458304deb25173a62ea50bc4cce5e3ebf223ccf9345e578ef7aa51657c21d6291eeb5840dcdb8d444e9f045e0702807060e358d69952a9cf8de567d206a7bf3984032f456fe917d16e9c6f3cc360203713087ae69042cf97ef22975b964194c0d3ce274440bb84680e9c04c2f45d1d5c594a25fd09af417a09f2c3670522820ed4614684658de3052e96bc9578bfbae397592ced8fbe2cecced5e9ce7e541eca706aac6d7c5f70885e95c2ae2b38235634319d75411b361a2fc82b88c4addc7cd87c23dbf64839ae1e9570be3bb1184657815741e779f2a48aea0555def882c158c5e1fda0cadcc6be92963d6bf3182efcf814879cbee880d9e59687623173f3dc30834019b7d79c3e90fef0d61185f53e93fb5203adbf8533c5ce406f2c2102df8a9de68a711a582e8d62aaa177fd6c62006db8446180e119350e31c9ceca827eba95e42abd94ba7e8c244dfd93716501d2a2dc333b51c87c83fc774a5dffec5c25847db73367b6fe8c03690c745b86b505a95bc4410c4cc5e7da22c4598fcfac02bceac0de9a438e875cc2b45867b21b4557364aa9050424fcc5b5b219cbcbfefef514a01c91120e8517ae6eb321d4c33b39a8d608618569220ca9c61a49fd3e6db8f25bfeda357e8438c83d386f1757f939936119b825e7f40d86175b15e5e445b06834ddae069e83cf52503f048d2b23f3329783308f4379d5ce1c11ee6c4b0824380cccaf590e82de8e1723c8898e0c135b75c8b1ac6a0192add605fd8634f96e1c88d9f2d85e828e3db03de8d009a33e00bdb96f11a3c2befba8a8ddf144cac7d247b9ff67ae815df4f8b8c93092828e6bbfead7a706dd6b643fbcc87ea9045e5c506e2fe07e81c202efd43e8c66e053dd3aaa2d34ed1fef6d37825c5977d36a6004dd9bfeae7ae9f7974351302e6dfb7f9d04cd9257531b33505fadd4b02f86e518f294384e785486a1b0a02c53e82a6faed01afc776fa2d9ea120d9490c86dd3f8151658ae7486c30a1d61a4898b3e31fb8b514395fb0538be5f0292425902553f021df13e74814bc212a9aba8c0b5c6ecfc733166eb2b3c18afc03e463d337eaf50a3ecee6e88bc94c1403c3f7a35047132d96d820fc9c6e8a6eb6b93cd0d762c5ca7e31e6b49d9a7be0111843c7a88bf19d435d1b256ddb478c685615cc3a007301cbf5e6a38b5182836d6477a80a24505c0778a59ad603b2c7d672384bf5467c2c12ace57bddba688556d80db8b50e09a36adb671c322d933ad916aef49f343388aff4e5679a000154e3ad82ad0948b123c4516569ab6be77690196ccff7cdba2ff799e52ff55160c11edc072bae1e7a4e66e14f9b4a63143ba63e90f0da1e4471245de4c40e3df0a517766b203ad4696cf012e9d02083cbdf91dafa8165c02d215172e44f55cd2c4a2591fdc4e3b8a72c987ac408d40d8c093cf0fd4da8d1323e22a7e419bc2606f577c39f016428fcf9025876c8f03aa483ff03f807d80cda92d4f9e40eef63ce05dce3bef00f9b821210c59414b9429a900c3ed9bfeb5d1e56579be39e46ced912e97fc8baec4917a628e73476edf00ffc43fd154a4391262fae7de3d1d93d76c00fe5e05c95eafa2a215c1f474be5f75f9179b76572abda252df0e35c23f3d35007203c4270fb713f3cefeb95924eeef0a540324b00d8ddb69459e31fcc506c29029963f33d80578f15e8814f964627730bdfd45901f4c46bafe1e33659b2d73495fe23b879e9192e02ed4381351100be99cba47d57574debe392e30051e710c199f9917ea8a921440cb955507e7b5fd7625014889d27b01eb1bae2c9013306cd1b7ebcb1c81eb49a0aac03036251f15b5ba93698ffa3f7d1e4b5e2c4f1436b6cadfe969aa6bca53212f27b3c481e37babcfbdf2e3c74a3543fe3e1b8551834bf3d06504032022fa14150e00b1514ac64d67a1bc00b4a406ca56ce10f0387e8d7bf3ec569e474b7ee07789ec36ee3283b22fb4d1eaab21c7e08d9e193be7af39915b124464da0283e38002a38d8b0aa450dc1ccfd1f8d1cac5727e09d0d4c84549d404b9726c2dadd84b8ae370bf272bb9f9460aaee8f8d41a022e0657741abcdcbd6fefa870bc8c89e57279682471a26063bb57568f883fdbe7ae0164bf8f62deb078929759d8991ab635abaee43472b25cced92b1a9c54ce6b3e01329ecfe6429dce76d3ca2bc35df4744e5d765faa0da33fe3cf3d7b1c80f98e0048d76aa0c128cb9ccc53d8a75377925b28508b4accbd878be8092ee889f83dfe5df4a1d00353c7c9c87ee38875a2c9d72e45d1963f41589af288d19a7e2f3df9713688fcb56012f55cdb45d1ff1c1f4c2640fef64d87a83938e71dc2285c7df435674104356d9064e4a7c2bb07fdfbb16d1a435407c4fce36fdc4b12a6e64df104796be6fa6e54154619f380eaca34ed8475d8798b6ea1d8b66e276aab9aadefe224a96fd6415ca6b45070746e58a90d64ed55313e320377fb9e03fdcee5fdeb192822430345aa177b0e8593e6af8858e91548072d3c2614cc6002e1a7c09deb0d926be692087669eeb408e969442af6eeade48c388de763f7057d46c38dede497c772ccbac24f0c7f83ac947a17af1f2460f99bb8028ac8ebee41ec4e802de65a5e66669b569607b0d485538f54ff02880e5597696d8199a227965c02ce9dde29f588431d0aaf43cacbd63299d98adb92857b190587e7e79dae6b58e2a06ddac887cca2209512a5a988a7ebe482040ed3b190cda4180d253534505ebbdb9dd835b6f13fdc6f37618426bec2125e02d54051ecd8e281e21a0b7c63654d538dd72b0ed00cde57ab664ac3799984f89672923f3603f0df718be366951933f94dd0a1a28e5ebbbe7c11d7ea23a2c68dea77973ae6cb8553d915696edf0a9f711dced079cf87758037a3fac8aede2fafd53071f1fa0a04fb4dbe9a38578ebba71dca80388894265df08d7961915370838ae26a9476b931fc85a2bfa6cfc9cbfd9dc95088749097207b57ba467707f1d0af606f961ba875a3d5406226cad4a1e49dc4b7ad1f0d5ec6b6d16b9a520fc2922e851de72b07a7aee058528258d866c80dc4b56fb59cc2c6972e7c087b766c81f5f1d6592e81e40c0ddbccd6ae6c2d093dbfa6583a18bb77b3748cc77e649797d6c8b4bc2285034dac6a2b5a7cc4eba4edc392928a9f7b768849323d81a0630ac573921f292baa51c7fc7c50a26c03291dbf7dde57b25c1a326208a9a23a7d5e9e69c9ac86114026a1aaed306aa9e758edbdb9ba168bee9f732a6184a234a5d15200886293838d0685f7f4505df7e1d3fdae61443cbc23c40fac2f340c1d6a973da5b4b29cb90afc9acaafca7ea779a4bdacb9558a3b5bdff5018acbf6b9f0a2cc6868162b1cad76f3b480d1facf9bd44da5636edb18ce861d4f2a4f7bd6973347fe6769799c62c20d3655054fa8c9f53da54ac84cbb93b8144e9ff65d275d82244795e6a8024e5b8f6d6003c257f3924da51fca28d467fdb2b82704542030a9d57d7de27ed83113bf6fea01ad9bf3d74da3da85f693633a5202cbf4e9af8e144c9d388a0ad8889c845cb7078f1e17c1cda1fcbc110565d2eb157200869bc6badc520d123908f76c4ff15039db456475ed9d37eeb6b467da58cd353aaa4ae7d7b01607beb31ef3fcd1f9ea0f4f265616fd9939c6101296b6d0185815b5053e33cb3aa261937d7847df7dae2196f4ed2cfd9610c20fca52f4592372d359ba3a98d016121841259ff7e76e5baf0b7858c65d92b386eb316f4d97ee35f44a6cab72f92b3eb6ba958d5955021fb02c466ae5bd8fc594ab918c4f924837f55840080060798cc3cb8345ded34aeda02f7d3ee62d8558b2aa540e04ee61ce47c15e6bdc519dba1ad51818367253bd8eb3a094af9d84f7fce3bc49b9cec3e67b3ac5bec1b48d69ebbffaf9f4a5abb5ec9c463f88dd759f610bb7b3ea573a0dc6e3b05e04619c7c70f6cb264f85e001a9b046c8906d718911fbcab427062f36d8e3f0e9c7fe4b68b1242c3f6535c8270a3fcfa7c59d710279dc2a78d6789864e77af27ee5d9537ddaceb94d73e714056c7056b9866d707fc3f76fc3e97394e25526c315fdab4d2ece06ce887904a58527ccc3391e6d6ba72944c8471b0e50962e8a4507a1aeae606fbf3d777f3ae44e4e5054d32b0d6b5e7c5c22c31bd0d8c3773e79a6d9f31ecfc874bbc8a05321095da846f9d1cd69864dec24b95d897d9a145c32e5c94bfec45ac83e663b5b48d70450f722c40d6938b6d2cde0740b50464e4baebcfd1fbf7121cda246eaee2c5c63a8bd509dad6821a55e2167e71f049d8d6f8d57381165d713cb0ed9d861ba3ac8b10af7180d66e9a7c46b734d78e745006d6cca696cd14f4458854b5c87d9f6bdff3ff8a92d65dc8dc1be9c4e16de514dd5201f7f8a59b374799f2053831be72b5fae3b174d5efa3dd6ba260d433a80ad3b8a9ef3b37b16a7980d8a1c31bbed3c03c76e32bd59a2e454d11e526788d8982879943375cf9268be50be859f77835b2f40fe74fd58ae8cf855de89a55a5ac597997888cd9b242793edca3edc08a2921a7004258d5dcdc622ead96fa18a1d26cc3782fc551ed8db2d71080857fd61c2f8bfbb041d52f4eda6b523066f0e39e19a17e8b47720803ce570f995e2cffafee5a0c4037d4fd57fccf05e2f902e17eea8dff4a9f4c198969151ee1e43bcb35cc971f80abd4a27ae8dd849471f58d94fd8cbf18d58e3cd38267b134fb2ab5e496f69d90a5d48939e986d267a1be1dafa2ad2ba0d7ab0df97fb0601389047e46487d03a6f2d477c121ffcdaa69ce0861947c51a1a10a30d4cff8a0b0fdea5993f1a528b253
Malware (1)
-
FamilyPublished 04/07/2025 10:12 · Modified 04/07/2025 10:12
Others (2)
- Uzbekistan
- Finance