Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
MalwareRansomware

deVixor

deVixor is an actively developed Android banking remote access trojan (RAT) with ransomware capabilities, reported by Cyble Research and Intelligence Lab (CRIL) as targeting Iranian users since at least October 2025. It evolved from an early SMS-harvesting malware into a full-featured platform for bank fraud, credential theft, device surveillance, and extortion. CRIL analyzed more than 700 samples and assessed with high confidence that it is part of a mass infection campaign operating at scale.

The malware is distributed as malicious APK files via phishing websites masquerading as legitimate automotive businesses and luring victims with heavily discounted vehicle offers. Reported distribution URLs include hxxp://asankhodroo[.]shop, hxxp://www[.]asan-khodro.store, hxxp://www[.]naftyar.info/naftman.apk, hxxp://abfayar[.]info/abfa.apk, hxxps://blupod[.]site/blupod.apk, hxxps://naftman[.]oghabvip.ir/naftman.apk, hxxp://vamino[.]online.infochatgpt.com/vamino.apk, and hxxps://lllgx[.]site/mm/V6.apk.

deVixor uses Telegram-based infrastructure for administration and rapid updates, including a Telegram bot-based admin panel and a Telegram channel used to publish version updates, promote capabilities, and share operational screenshots. Each deployed APK is assigned a unique Bot ID stored locally in port.json. Operationally, it uses Firebase for command delivery and a separate decrypted C2 URL/server for data exfiltration.

Its capabilities include harvesting SMS-based financial data such as OTPs, account balances, card numbers, and messages from Iranian banks and cryptocurrency exchanges; scanning up to 5,000 SMS messages; keylogging; notification theft; screenshot capture; contact theft; gallery/media theft; device surveillance; anti-uninstall and stealth features; Google Play Protect bypass techniques; and extensive abuse of Android Accessibility Service. It also performs credential theft through WebView-based JavaScript injection by loading legitimate banking pages and stealing usernames and passwords entered into login forms, and can generate fake bank notifications to drive victims into those flows.

The malware shows strong regional specialization against Iranian financial institutions, payment services, and cryptocurrency platforms. Reported targeted banks and services include Bank Melli Iran, Bank Mellat, Bank Tejarat, Bank Saderat Iran, Bank Sepah, Bank Maskan, Bank Keshavarzi, Bank Refah, Bank Pasargad, Bank Parsian, Bank Ayandeh, Bank Saman, Bank Sina, Bank Dey, Post Bank Iran, Middle East Bank, Iran Zamin Bank, Eghtesad Novin Bank, Karafarin Bank, Shahr Bank, Hekmat Iranian Bank, Industry & Mine Bank, Export Development Bank of Iran, Tavon Bank, BluBank, and Iran Kish. Reported targeted cryptocurrency exchanges include Binance, CoinEx, Ramzinex, Exir, Tabdeal, Bitbarg, TetherLand, AbanTether, OkExchange, ArzDigital, IranCryptoMarket, Cryptoland, Bitex, and Excoino.

deVixor also includes a remotely triggered ransomware module activated via a RANSOMWARE command. The module stores the ransom note, TRON wallet address, and demanded amount in LockTouch.json to persist across reboots. Reported ransom messaging includes "Your device is locked. Deposit to unlock," and Telegram-posted screenshots described a demand of 50 TRX. Overall, the reporting describes deVixor as a maintained, service-like criminal platform combining financial theft, persistent device control, and extortion in a single Android malware family.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

MITRE ATT&CK

Techniques & procedures

7 distinct techniques documented for this family, organized by ATT&CK tactic.

Initial Access

1 technique
T1566PhishingEvidence2

"...targeting Iranian users through phishing websites that masquerade as legitimate automotive businesses promising deep discounts to lure users into downloading malicious APK files."

Execution

1 technique
T1648Serverless ExecutionEvidence1

"...Google Play Protect bypass techniques, and exploitation of Android’s Accessibility Service."

Credential Access

3 techniques
T1056Input CaptureEvidence1

"...adding banking-related overlay attacks, keylogging..." and "...collect all device notifications, capture keystrokes..."

T1056.003Web Portal CaptureEvidence1

"...adding banking-related overlay attacks..."

T1056.004Credential API HookingEvidence1

"It captures banking credentials by loading legitimate banking pages inside a WebView-based JavaScript injection."

Collection

3 techniques
T1056Input CaptureEvidence1

"...adding banking-related overlay attacks, keylogging..." and "...collect all device notifications, capture keystrokes..."

T1056.003Web Portal CaptureEvidence1

"...adding banking-related overlay attacks..."

T1056.004Credential API HookingEvidence1

"It captures banking credentials by loading legitimate banking pages inside a WebView-based JavaScript injection."

Command and Control

1 technique
T1102Web ServiceEvidence1

"The Android banking malware uses Firebase for command delivery..." | "...leveraging Telegram-based infrastructure, enabling centralized control, rapid updates..." and "The RAT uses a Telegram bot–based admin panel for issuing commands..."

Impact

1 technique
T1486Data Encrypted for ImpactEvidence2

"...includes a remotely triggered ransomware module capable of locking devices and demanding cryptocurrency payments..."

INDICATORS OF COMPROMISE

IOCs tracked for this family

16 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.

View more in app
Network
8 tracked

IPs, domains, and DNS infrastructure linked to this family.

Other
8 tracked

Other indicator types observed in public reporting.

TypeValueLatest sighting
domain●●●●●●●●●●●●View more in app5 months ago
uri●●●●●●●●●●●●View more in app5 months ago
uri●●●●●●●●●●●●View more in app5 months ago
uri●●●●●●●●●●●●View more in app5 months ago
uri●●●●●●●●●●●●View more in app5 months ago
uri●●●●●●●●●●●●View more in app5 months ago
ACTIVITY FEED

Recent activity

9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.

the hacker newsNews
Mar 20, 2026
Google Adds 24-Hour Wait for Unverified App Sideloading to Reduce Malware and Scams

Named as one of 17 Android malware families detected in the wild over four months.

Read more
the hacker newsNews
Feb 16, 2026
New ZeroDayRAT Mobile Spyware Enables Real-Time Surveillance and Data Theft

Android banking trojan targeting Iranian users via phishing sites since 2025-10; steals sensitive info and includes a remotely triggered ransomware-like module that locks devices and demands cryptocurrency; uses Firebase for commands and Telegram bots for administration.

Read more
thecyberexpress com vulnerabilitiesNews
Jan 16, 2026
TCE Weekly Roundup: Stories For NSA, Iran Blackout, And More

Android-focused banking malware/RAT offered as a service-based criminal platform; distributed via phishing sites as malicious APKs and combines credential theft, device surveillance, and ransomware-like functionality. Uses Telegram and Firebase infrastructure for operations.

Read more
scworldNews
Jan 15, 2026
New Android malware ‘deVixor’ adds ransomware capabilities | SC Media

Android banking malware that evolved into a full-featured remote access trojan with credential theft (including JavaScript injection on banking pages), SMS/OTP harvesting, keylogging, notification theft, user surveillance, and anti-uninstall/stealth features; additionally includes a ransomware module that locks devices and demands cryptocurrency payment, persisting across reboots by storing infection details locally.

Read more
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching16

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping7

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.