Blazefang is a financially motivated cybercriminal threat actor involved in Android malware campaigns targeting Telegram users in Uzbekistan. It has been identified as one of the principal groups participating in a broader wave of Uzbekistan-focused mobile banking and SMS-stealer activity alongside TrickyWonders and Ajina. The actor’s operations rely on Telegram-centric social engineering to distribute malicious Android applications, gain access to victims’ devices and phone numbers, compromise Telegram accounts, and propagate further by sending malicious apps to contacts from hijacked accounts. Blazefang-associated activity is linked to the delivery and use of Android malware families observed in the campaign, including SMS stealers, banking malware, and droppers such as Wonderland, MidnightDat, RoundRift, Ajina.Banker, and Qwizzserial. The malware is used to steal credentials and money from infected devices, including repeated theft enabled by persistent access to SMS and device functions. Operational tradecraft includes disguising malware as legitimate applications, using droppers that appear benign during initial inspection, embedding payloads deeper in the infection chain, requesting extensive permissions, and presenting deceptive prompts to mislead users about removal. The actor demonstrates increasing operational maturity through obfuscation, anti-analysis measures, and frequent rotation of package names and delivery infrastructure to hinder detection and blacklisting. Observed behaviors support capabilities in initial access, credential theft, session hijacking through Telegram account abuse, persistence on infected devices, defense evasion, and financial exfiltration from victim accounts.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
5 malware families attributed to this actor across reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Blazefang is a threat actor group targeting Uzbekistan with Android banking trojans for financial theft.
One of the threat groups involved in Uzbekistan-focused Android SMS-stealer activity leveraging Telegram for distribution and propagation, aiming to steal banking credentials and funds.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.