Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
5 malware families

blazefang

Also known asblazefang

Blazefang is one of three main threat actors identified by Group-IB as targeting Telegram users in Uzbekistan in a wave of Android malware activity that began in October 2025, alongside TrickyWonders and Ajina. The group is associated with campaigns distributing malicious Android APKs via Telegram-based social engineering, using stolen Telegram access to message victims and propagate malware through victims’ contact lists. The activity is aimed at stealing money and credentials from infected Android devices. Group-IB reported the broader campaign used malware including SMS stealers and droppers such as Wonderland, MidnightDat, RoundRift, Ajina.Banker, and Qwizzserial. The infection chains used droppers that appeared benign while embedding stealers, helping them pass standard security checks and complicate early detection. Reported tactics in this activity include masquerading as legitimate applications such as Google Play, requesting permissions, displaying deceptive uninstall prompts, using obfuscation and anti-analysis functions, and frequently rotating domains and package names. Group-IB described the updated infection chain used by the Uzbekistan-targeting actors as a significant increase in operational maturity. No additional aliases or subgroup information for Blazefang were provided in the content.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal5

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables

Domains, IPs, and hashes tied to this actor, refreshed continuously.