Threats Tagged 'otp interception'
View all threats tagged with 'otp interception'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'otp interception'
Click on any threat for detailed analysis and mitigation recommendations
A sophisticated Android malware campaign has been identified conducting carrier billing fraud through premium SMS abuse across Malaysia, Thailand, Romania, and Croatia. The operation comprises nearly 250 malicious applications that selectively target users based on their mobile operators, silently subscribing victims to premium services without consent. The malware demonstrates advanced capabilities including precise regional targeting with hardcoded SIM operator validation, automated subscription workflows using WebView manipulation and JavaScript injection, OTP interception via abuse of Google's SMS Retriever API, and Telegram-based exfiltration of device metadata. The campaign impersonates popular applications including Facebook, Instagram, TikTok, Minecraft, and Grand Theft Auto to lure victims. Active from March 2025 through January 2026, the operation employs three distinct variants with increasing levels of sophistication, utilizing distributed command and control infrastructure and systematic refer... Join the discussion | AlienVault OTX General | 05/20/2026, 22:37:47 UTC Added: 05/21/2026, 16:59:45 UTC |
A sophisticated Android malware campaign distributes a malicious 'RTO Challan / e-Challan' APK via WhatsApp, targeting users with a fraudulent payment app. The malware employs advanced obfuscation and hidden installation techniques to maintain persistence and control over infected devices. It establishes a custom VPN tunnel to conceal network traffic and harvests extensive personal, device, and financial data. Key capabilities include OTP interception, call behavior manipulation, and presenting fake payment interfaces to steal banking credentials. The command-and-control infrastructure uses obfuscated Base64-encoded URLs linked to malicious domains. This campaign combines social engineering, mobile malware, and financial fraud, posing a significant risk of monetary loss and identity theft. Although no CVSS score is assigned, the threat severity is assessed as high due to the impact and exploitation ease. European organizations with Android users, especially those using WhatsApp and mobile banking, should be vigilant. Mitigation requires targeted user awareness, mobile security hygiene, and network monitoring for suspicious VPN tunnels and domain connections. Join the discussion | AlienVault OTX General | 12/12/2025, 10:09:15 UTC Added: 12/12/2025, 12:53:34 UTC |
Showing 1 to 2 of 2 results