Massive Android Malware Campaign Steals OTPs and Identities Worldwide: 107,000 Apps, 113 Countries, and Counting

Malicious Android apps have been stealing SMS messages, including OTPs, from over 600 global brands since February 2022. With more than 107,000 malware samples detected, these apps trick users via deceptive ads and Telegram bots, affecting victims in 113 countries. The malicious apps intercept OTPs…

Hot Take:

Looks like our trusty phones are turning into snitches, spilling our OTP secrets faster than a reality TV star at a reunion episode. Who knew installing that knock-off Microsoft Word app could lead to this much drama?

Key Points:

  • Over 107,000 malicious Android apps detected, primarily targeting OTPs for identity fraud.
  • Malicious apps intercepted OTPs from 600 global brands, affecting users in 113 countries.
  • Attackers distribute these apps via deceptive ads and 2,600 Telegram bots.
  • Stolen SMS messages are sent to 13 command-and-control servers.
  • Threat actors use stolen data for creating fake accounts and further fraudulent activities.

Membership Required

 You must be a member to access this content.

View Membership Levels
Already a member? Log in here