blazefang
Blazefang is one of three main threat actors identified by Group-IB as targeting Telegram users in Uzbekistan in a wave of Android malware activity that began in October 2025, alongside TrickyWonders and Ajina. The group is associated with campaigns distributing malicious Android APKs via Telegram-based social engineering, using stolen Telegram access to message victims and propagate malware through victims’ contact lists. The activity is aimed at stealing money and credentials from infected Android devices. Group-IB reported the broader campaign used malware including SMS stealers and droppers such as Wonderland, MidnightDat, RoundRift, Ajina.Banker, and Qwizzserial. The infection chains used droppers that appeared benign while embedding stealers, helping them pass standard security checks and complicate early detection. Reported tactics in this activity include masquerading as legitimate applications such as Google Play, requesting permissions, displaying deceptive uninstall prompts, using obfuscation and anti-analysis functions, and frequently rotating domains and package names. Group-IB described the updated infection chain used by the Uzbekistan-targeting actors as a significant increase in operational maturity. No additional aliases or subgroup information for Blazefang were provided in the content.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Associated malware families
5 malware families attributed to this actor across reporting.
Recent activity
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Blazefang is a threat actor group targeting Uzbekistan with Android banking trojans for financial theft.
One of the threat groups involved in Uzbekistan-focused Android SMS-stealer activity leveraging Telegram for distribution and propagation, aiming to steal banking credentials and funds.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.