Threats Tagged 'sms'
View all threats tagged with 'sms'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'sms'
Click on any threat for detailed analysis and mitigation recommendations
A targeted campaign has been identified distributing a trojanized version of the Red Alert rocket warning Android app to Israeli users via SMS messages impersonating official Home Front Command communications. The malicious app retains full rocket alert functionality while running malicious code in the background. It bypasses Android security checks through certificate spoofing and runtime manipulation. Once installed, the malware collects sensitive data including SMS messages, contacts, location data, device accounts, and installed applications. The stolen data is transmitted to a remote command-and-control server. This campaign exploits user trust in emergency services during periods of geopolitical tension, combining social engineering with mobile espionage for maximum impact. Join the discussion | AlienVault OTX General | 03/06/2026, 15:21:48 UTC Added: 03/09/2026, 10:21:50 UTC |
Fantasy Hub is a newly identified Android Remote Access Trojan (RAT) offered as Malware-as-a-Service (MaaS) on Russian-language platforms. It provides extensive espionage capabilities including SMS exfiltration, contact and call log theft, and bulk media extraction. The malware can intercept, reply to, and delete incoming notifications, and uses fake Google Play pages to evade detection. It specifically targets financial institutions by deploying fake windows to steal banking credentials. The MaaS model includes comprehensive documentation and a bot-driven subscription system, lowering the barrier for novice attackers. Although no known exploits in the wild have been reported yet, the threat poses a medium severity risk due to its broad capabilities and ease of use. European organizations, especially financial institutions, are at risk due to the malware’s targeting profile and Android’s widespread use. Mitigation requires targeted detection of fake app pages, enhanced mobile security hygiene, and user awareness focused on banking credential phishing. Countries with large financial sectors and high Android adoption, such as Germany, France, and the UK, are most likely to be affected. Join the discussion | AlienVault OTX General | 11/10/2025, 11:34:25 UTC Added: 11/10/2025, 11:50:41 UTC |
ClayRat is an Android spyware campaign primarily targeting Russian users by masquerading as popular apps distributed through Telegram channels and phishing sites. It exfiltrates SMS, call logs, notifications, device info, takes photos, and sends SMS messages. The malware spreads aggressively by sending malicious links to victims' contacts, leveraging Android's default SMS handler role to bypass permission prompts. Over 600 samples and 50 droppers have been observed in three months, with continuous obfuscation improvements. The campaign uses impersonation, community distribution, UX deception, and self-propagation via SMS forwarding. While currently focused on Russia, the techniques and propagation methods pose risks to European organizations with Android users. No known exploits are publicly reported, and the campaign requires user interaction to install and propagate. Suggested severity is medium due to its impact on confidentiality and propagation capabilities but limited to targeted regions and requiring user action. Join the discussion | AlienVault OTX General | 10/10/2025, 08:17:49 UTC Added: 10/10/2025, 08:36:17 UTC |
Showing 1 to 3 of 3 results