216.73.217.22

Discovery of Qwizzserial: A New Android SMS Stealer Family

· Published 04/07/2025 10:12 · Modified 04/07/2025 10:49

Export JSON

Essential information

Published
04/07/2025 10:12
Modified
04/07/2025 10:49
Tags
2025-07-04 financial fraud qwizzserial sms stealer
Related entities
200 observables, 1 malware, 2 others

Description

A new Android family, named , has been uncovered, primarily targeting users in Uzbekistan. The malware exploits the reliance on SMS for two-factor authentication in local payment systems, allowing fraudsters to intercept SMS messages and gain control over victims' finances. Distributed through Telegram, the campaign mirrors the structure of Classiscam. The stealer has infected approximately 100,000 users, resulting in financial losses of at least US$62,000. The malware's effectiveness stems from the widespread use of SMS for various financial transactions in Uzbekistan, including P2P transfers, payments, and authorization confirmations, often serving as the sole security layer in the absence of 3D Secure or biometric authentication.

External references