A financially motivated group is targeting Indonesian and Vietnamese Android users with banking trojans disguised as government and payment apps. The campaign uses spoofed Google Play Store pages and a WebSocket-based APK delivery mechanism to evade detection. The trojans, primarily BankBot variants, steal credentials and bypass two-factor authentication.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
7 events from the most recent confirmed update back to the earliest known activity.
Security reporting identified 'BlockBlasters' on Steam as being used to deliver malware to users. The event marks a software distribution abuse case in which a game platform listing was leveraged for malware delivery.
Researchers revealed a campaign using a legitimate tool as part of the infection chain to deploy remote access trojans. The disclosure highlighted abuse of trusted software to evade suspicion and gain persistent access.
A malware campaign targeting Android users in Southeast Asia was disclosed, using trojans disguised as government and payment applications. The operation focused on credential and financial theft through impersonated mobile apps.
Researchers reported on Kawa4096 as a newly identified ransomware group, noting branding similarities to Akira and ransom-note characteristics resembling Qilin. The disclosure marks the public emergence of a distinct ransomware operation.
Researchers disclosed a malicious IIS module campaign, also reported as BadIIS, that hijacks websites by redirecting traffic and planting web shells on compromised Microsoft IIS servers. The reporting describes a web-server malware operation affecting site integrity and visitor traffic.
GitHub announced new npm supply-chain security requirements mandating two-factor authentication and short-lived publishing tokens. The move was presented as a hardening measure to reduce account compromise and package publishing abuse.
Security researchers discovered a malicious npm package named 'fezbox' that concealed a second-stage payload in a QR code image to deliver cookie- and credential-stealing malware. Multiple outlets reported the same package and technique, indicating a single newly disclosed supply-chain malware event.
11 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcedarkreading.com
Open sourcesecurityonline.info
Open sourcethehackernews.com
Open sourcesecurityonline.info
Open sourcesecurityonline.info
Open sourcebleepingcomputer.com
Open sourcesecurityonline.info
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.