216.73.217.22

FinStealer

· Published 17/02/2025 11:03 · Modified 17/02/2025 11:22

Export JSON

Essential information

Published
17/02/2025 11:03
Modified
17/02/2025 11:22
Tags
2025-02-17 CVE-2011-2688 android banking c2 servers credential-theft finstealer mobile phishing sql injection telegram trojan.rewardsteal/joxpk xor encryption
Related entities
1 vulnerabilities (cve), 5 observables, 1 malware, 3 others

Description

A sophisticated malware campaign exploits a leading Indian bank's brand through fraudulent applications. Distributed via links and social engineering, these fake apps mimic legitimate bank apps, tricking users into revealing sensitive information. The malware uses advanced evasion techniques, including encrypted communication with , dynamic payload execution, and runtime behavior alterations. The attackers aim for financial gain through credential theft, unauthorized transactions, and data sale on darknet forums. The campaign employs bots, attacks, and . The analysis highlights the threat's impact and provides recommendations for mitigation, including advanced monitoring, vulnerability patching, and user education.

External references