Researchers at ThreatFabric reported a new Android banking trojan dubbed Massiv that is distributed via fake IPTV applications and is designed to enable device takeover (DTO) for financial fraud. Once installed, Massiv supports credential theft and account compromise via screen overlays, keylogging, SMS interception, and screen streaming using Android’s MediaProjection API, allowing operators to remotely control infected devices and perform fraudulent transactions from victims’ banking sessions.
ThreatFabric observed targeted campaigns that included overlays impersonating Portugal’s gov.pt app and its associated Chave Móvel Digital (CMD) digital authentication/signature ecosystem, aiming to capture phone numbers and PINs to help bypass KYC checks and access broader public/private services. The reporting also describes downstream abuse where stolen identity and authentication data was used to open new bank accounts in victims’ names for fraud and money laundering; Massiv’s remote-control capabilities include both live screen streaming and an Accessibility Service-based “UI-tree” mode that extracts structured UI data (e.g., element names, coordinates, and attributes) to automate interactions and potentially bypass screen-capture protections used by banking and other sensitive apps.

Pull IOCs and campaign context straight into your stack.
5 events from the most recent confirmed update back to the earliest known activity.
ThreatFabric said Massiv remains under active development and noted the addition of API keys for backend communications. Researchers assessed this could indicate movement toward a more scalable malware-as-a-service-style operation, though it was not yet seen being advertised as MaaS.
On February 19, 2026, multiple outlets reported ThreatFabric's disclosure of Massiv, a new Android banking trojan spread through fake IPTV apps. The malware supports overlays, keylogging, SMS interception, and remote device control using MediaProjection-based screen streaming and Accessibility-based UI-tree extraction.
ThreatFabric observed cases in which data stolen through Massiv was used to open new bank and service accounts in victims' names. These accounts could then support money laundering, fraudulent loans, and cash-out schemes.
In an observed campaign, Massiv targeted Portugal's gov.pt application tied to Chave Móvel Digital, prompting victims for phone numbers and PINs. The stolen identity data was likely used to bypass KYC and gain access to banking and other services.
ThreatFabric reported a broader rise in IPTV-themed Android malware droppers over the prior six to eight months, exploiting users' tendency to sideload IPTV apps from unofficial sources. The activity primarily affected users in Spain, Portugal, France, and Turkey.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
5 references tracked. Mallory keeps watching after this page renders.
blog.polyswarm.io
Open sourcescworld.com
Open sourcethehackernews.com
Open sourcebleepingcomputer.com
Open sourcegovinfosecurity.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.