Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
credential-stealer-activityremote-access-implantphishing-campaign-intelligencecommand-and-control-method

Mobile-Focused Threat Activity: Android Banking Trojan deVixor and QR-Code Phishing Growth

Updated 3mo agoFirst seen Jan 14, 20262 sources

Reporting highlights an Android banking malware campaign dubbed deVixor that has been aggressively targeting Iranian users and has evolved from an SMS harvester into a modular RAT with banking fraud, surveillance, and a remotely triggered ransomware capability. Distribution is described as malicious APKs delivered via phishing sites masquerading as legitimate businesses; once installed, the malware requests extensive permissions to steal SMS/OTP data, card and account details, and content from banks and cryptocurrency services. The tooling reportedly supports WebView/JavaScript injection to capture credentials, keylogging and media theft (e.g., screenshot/gallery collection), and uses Telegram for command-and-control.

Separate reporting notes a surge in QR code phishing (“quishing”) against mobile users in 2025, where QR codes are used to redirect victims to credential-harvesting or otherwise malicious sites—reinforcing that mobile users are being targeted through multiple social-engineering delivery paths beyond traditional links. Two additional items reference a China-nexus actor (UAT-7290) targeting telecoms and Astaroth (“Boto Cor-de-Rosa”) banking malware pivoting to WhatsApp, but the provided excerpts contain insufficient detail to confirm they describe the same specific mobile-banking event as deVixor or the same QR-phishing reporting.

Share:
Mobile-Focused Threat Activity: Android Banking Trojan deVixor and QR-Code Phishing Growth
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

4 events from the most recent confirmed update back to the earliest known activity.

4 EVENTS
Jan 14, 20265mo ago

CRIL publicly reports deVixor campaign details

On publication, Security Online summarized CRIL's findings on the deVixor Android malware campaign, including its focus on Iranian banking and cryptocurrency users and its expanded RAT and ransomware capabilities. This marked the public disclosure of the campaign's technical details and targeting patterns.

Dec 31, 20256mo ago

Report highlights surge in QR code phishing attacks targeting mobile users

A report cited by Zimperium said QR code-based phishing attacks surged during 2025, with campaigns redirecting mobile users to malicious websites designed to steal credentials and other sensitive data. The activity was presented as part of Zimperium's Mobile Threat Watch coverage and attributed to reporting from Cybersecurity Insiders.

Oct 1, 20259mo ago

deVixor evolves into a modular banking trojan and RAT

During the campaign, deVixor reportedly evolved from an SMS harvester into a more capable Android malware platform with banking fraud, surveillance, credential theft, keylogging, data exfiltration, and device-locking ransomware functions. The malware used WebView-based credential theft against banks and crypto services and relied on Telegram for command-and-control.

deVixor Android malware campaign begins targeting Iranian users

Cyble Research and Intelligence Lab reported that the deVixor Android banking malware campaign has aggressively targeted users in Iran since October 2025. The malware was distributed through phishing websites impersonating legitimate automotive businesses to trick victims into installing malicious APKs.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

7 LINKEDOpen in app
Malware
1 linked
Affected products
2 linked
AndroidTelegram
Organizations
3 linked
CybleZimperiumCybersecurity Insiders
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.