Wednesday , June 24 2026
deVixor

Android Banking Malware “deVixor” Targets Users with Ransomware capabilities

A new Android banking trojan called deVixor poses a serious risk to mobile users, featuring financial data theft, device surveillance, and ransomware in one malicious tool.

The malware, active since October 2025, is a significant threat to Android users, luring victims with fake car websites and using Telegram for control.

LastPass says hackers stole customer data via Klue, supply chain breach

LastPass has reported a security issue with its vendor, Klue. This incident allowed an attacker unauthorized access to customer data....
Read More
LastPass says hackers stole customer data via Klue, supply chain breach

New Apple Exploit Bypasses Boot Defenses, Possibly Affects Millions of iPhones Worldwide

Researchers at cybersecurity firm Paradigm Shift found a new flaw called usbliter8. This flaw can get around main boot protections...
Read More
New Apple Exploit Bypasses Boot Defenses, Possibly Affects Millions of iPhones Worldwide

India’s Tata Electronics hit by cyber breach: Hacker target 630 GB record

A cyber attack seems to have affected one of India's top electronics companies. Tata Electronics has said there was a...
Read More
India’s Tata Electronics hit by cyber breach: Hacker target 630 GB record

Anthropic’s Mythos reportedly broke NSA classified systems in hours

The recent finding shows how powerful Mythos is: the AI can access the US government's secret networks in just a...
Read More
Anthropic’s Mythos reportedly broke NSA classified systems in hours

OpenAI New Method “Deployment Simulation” Predicts AI Risks Before Deployment

Test before going live is important for AI developers. But there's a problem: testing usually uses fake scenarios that often...
Read More
OpenAI New Method “Deployment Simulation” Predicts AI Risks Before Deployment

AryStinger botnet infected thousands of D-Link routers globally

AryStinger has taken control of over 4,000 old D-Link routers to use them as proxies for harmful traffic. The team...
Read More
AryStinger botnet infected thousands of D-Link routers globally

Hacker suspected of sending alerts across Brazil

Brazil's government suspects a hacking attack triggered an unauthorized ‌alert sent to cell phones across parts of the country early...
Read More
Hacker suspected of sending alerts across Brazil

CyberSentinel AI features 33 security tools like Nmap, SQLMap, and ZAP, utilizing Claude and GPT

A new open-source cybersecurity tool named CyberSentinel AI v3.0 has come out. It is an important step in self-operated security...
Read More
CyberSentinel AI features 33 security tools like Nmap, SQLMap, and ZAP, utilizing Claude and GPT

Barracuda hosts Dhaka roundtable on cyber resilience

Barracuda gathered industry people in Dhaka on 18 June 2026 for a roundtable talk about cyber resilience. The company shared...
Read More
Barracuda hosts Dhaka roundtable on cyber resilience

CISA Alerts Fortinet Users as FortiBleed Affects 86,644 FortiGate Devices

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) asked Fortinet users with FortiGate devices on Thursday to act to protect...
Read More
CISA Alerts Fortinet Users as FortiBleed Affects 86,644 FortiGate Devices

The malware spreads through fake websites pretending to be real car businesses, attracting victims with low-priced vehicle deals.

Cyble Research and Intelligence Lab (CRIL) analyzed over 700 samples and found a widespread infection campaign by threat actors using misleading distribution techniques.

The campaign uses advanced social engineering, with fake domains like asankhodroo[.]shop, asan-khodro.store, and naftyar.info spreading malware.

Evidence shows that the operation targets Iranian users, indicated by language used in Telegram messages, Persian phishing schemes, and a focus on Iranian banks and local cryptocurrency exchanges, highlighting the regional threat.

The malware gathers financial data from SMS by scanning up to 5,000 messages for OTPs, account balances, card numbers, and messages from banks and crypto exchanges.

The trojan specifically targets 26 Iranian banks like Bank Melli Iran, Bank Mellat, Bank Tejarat, and Bank Saderat Iran, as well as 14 cryptocurrency exchanges including Binance, CoinEx, Ramzinex, and Exir.

deVixor uses WebView-based JavaScript injection attacks to steal banking credentials, in addition to SMS harvesting.

deVixor has a troubling feature: it can trigger ransomware remotely. When attackers use the “RANSOMWARE” command, it locks the victim’s device and shows a message demanding cryptocurrency for release.

Based on screenshots shared on the threat actor’s Telegram channel, victims see a message stating “Your device is locked. Deposit to unlock” along with a TRON cryptocurrency wallet address and a demand of 50 TRX tokens.

The latest versions support over 50 commands for total device control, including keystroke capture, screenshot collection, notification access, contact extraction, gallery access, and app disguise.

Figure 6 – Firebase command execution (left) and decryption of C&C server URL (Right)

Version 2 introduced additional commands such as SEARCH_ALL_SMS for keyword-based message searching, NOTIFICATION_READER for collecting device notifications, and GET_ALL_SENT_SMS for exfiltrating sent message history.

Check Also

CISA

CISA: Splunk flaw under active exploit, patch by Sunday

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has asked federal agencies to protect their …