216.73.216.6

Frogblight banking Trojan targets Android users in Turkey

· Published 15/12/2025 13:00 · Modified 21/12/2025 19:03

Export JSON

Essential information

Published
15/12/2025 13:00
Modified
21/12/2025 19:03
Tags
2025-12-15 android banking trojan coper frogblight persistence remote access smishing spyware turkey
Related entities
6 observables, 6 others

Description

A new called has been discovered targeting users in . Initially disguised as an app for accessing court case files, it later adopted more universal disguises like the Chrome browser. can steal banking credentials through official government websites and has capabilities to collect SMS messages, app lists, and device information. It can also send arbitrary SMS messages. The malware has been actively updated with new features, indicating ongoing development. Distribution likely occurs through attacks convincing users they are involved in court cases. uses sophisticated techniques for remote device control, , and protection against deletion. The majority of victims are located in , and the developers likely speak Turkish.

External references