Lazarus Stealer is an Android infostealer described by CYFIRMA as a new Android banking trojan observed in the wild. It has been reported disguised as "GiftFlipSoft" and targets multiple Russian banking applications. Available reporting indicates it functions primarily as an infostealer, while some observed features suggest it can also operate as a banking trojan. High-confidence details in the provided content are limited to its Android platform, its disguise as GiftFlipSoft, and its targeting of Russian banking apps.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Android banking trojan/stealer disguised as a benign app, targeting Russian banking apps to steal card data, PINs, and credentials using SMS/overlay/usage-access permissions and WebView-based phishing.
Lazarus Stealer is an Android infostealer with features that may also allow it to function as a banking trojan, targeting sensitive user data and potentially financial information.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.