UdangaSteal is an Android banking/SMS-stealing malware family tracked by Kaspersky as Trojan-Banker.AndroidOS.UdangaSteal. Kaspersky reported observing a campaign in 2023 and early 2024 under the detection name HEUR:Trojan-Banker.AndroidOS.UdangaSteal that primarily targeted victims in Indonesia, Malaysia, and India. The malware was used to steal SMS data and exfiltrate it to attacker-controlled Telegram bots used as C2. Kaspersky also noted members of the UdangaSteal family active in Indonesia and India, and ranked UdangaSteal.b among notable mobile banker detections in its telemetry. The provided content does not include additional high-confidence details on infection vector, specific permissions, or technical indicators beyond the Telegram-bot exfiltration and regional targeting.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct techniques documented for this family, organized by ATT&CK tactic.
6 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Android banking trojan/stealer listed among the top mobile banker detections in 2024.
An Android banking malware family/st ealer variant newly appearing in the 2024 rankings.
Android malware observed in 2023 and early 2024 that stole SMS data and exfiltrated it to Telegram bots. It used multiple social-engineering lures including wedding invitations, parcel delivery, credit card transactions, and government-themed messages.
An Android banking Trojan variant observed targeting users in Indonesia.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.