Researchers have identified a sophisticated scam campaign that targets seniors worldwide through Facebook groups promoting social activities, such as dance events, day trips, and community gatherings. The campaign first emerged in Australia in August, with users reporting suspicious Facebook groups that appeared to cater specifically to older adults. Cybersecurity firm ThreatFabric later discovered that the operation had expanded to other countries, including Singapore, Malaysia, Canada, South Africa, and the United Kingdom. The scammers use AI-generated content to make the Facebook group posts appear legitimate and engaging, successfully attracting hundreds of responses from potential victims. Once individuals express interest in the advertised events, the fraudsters initiate private conversations via Facebook Messenger or WhatsApp. During these conversations, victims are directed to fake registration websites that prompt them to download a so-called "community app" to participate in the activities. Instead of a legitimate app, the download link either directly installs the Datzbro Android malware or uses a dropper known as Zombinder to bypass security protections on newer Android devices. Datzbro is a newly emergent Android banking trojan with advanced spyware capabilities, including audio recording, camera access, file theft, and keylogging. The malware also features a remote control mode that allows attackers to exfiltrate on-screen information, steal lock screen PINs, and harvest credentials for financial services such as Alipay, WeChat, and cryptocurrency or bank accounts. The campaign leverages the trust and community orientation of seniors, making them particularly vulnerable to these social engineering tactics. The widespread availability of Datzbro's builder and command-and-control software, following a leak online, has increased the risk of further global proliferation. Security researchers warn that the combination of convincing AI-generated lures and sophisticated malware delivery mechanisms represents a significant evolution in mobile threat campaigns. The use of Zombinder as a dropper enables the malware to evade many standard Android security measures, increasing the likelihood of successful infections. The campaign's global reach and focus on a vulnerable demographic underscore the need for increased awareness and targeted security education for seniors. Financial fraud, device takeover, and credential theft are among the primary risks associated with this campaign. The incident highlights the growing trend of cybercriminals exploiting social media platforms and AI technologies to orchestrate large-scale, targeted attacks. Ongoing monitoring and collaboration between cybersecurity firms and social media companies are essential to disrupt such operations and protect at-risk populations.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
ThreatFabric reported that Datzbro had become a broader global threat because its builder and command-and-control software leaked online, lowering the barrier for other criminals to use the malware.
Analysis of the campaign revealed the Android malware Datzbro, delivered directly or through the Zombinder dropper. The malware combines spyware and banking-trojan functions, enabling device takeover, credential theft, and financial fraud.
After its initial detection, the scam was observed targeting users in Singapore, Malaysia, Canada, South Africa, and the U.K. The operation used convincing posts, then moved victims to Messenger or WhatsApp and on to fake registration sites distributing malware.
Researchers first noticed a scam campaign in Australia in August 2025 that used Facebook groups advertising social activities for seniors to lure victims toward malicious Android app installs.
3 references tracked. Mallory keeps watching after this page renders.
malwarebytes.com
Open sourcetherecord.media
Open sourcescworld.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.