Android SMS-Stealing Malware Campaign Evolves in Uzbekistan
Group-IB reported a new stage in the evolution of Android SMS-stealing malware targeting users in Uzbekistan, indicating that threat actors are continuing to refine mobile malware operations aimed at intercepting text messages. Such malware is commonly used to capture one-time passwords, banking verification codes, and other sensitive communications that can enable account takeover, financial fraud, and unauthorized access to online services.
The report indicates that the activity is part of a broader shift in mobile threat tactics, with attackers adapting their tooling and lures to improve infection success and persistence on Android devices. The campaign highlights ongoing risk to mobile users and organizations that rely on SMS-based authentication, underscoring the need for stronger mobile security controls, user awareness, and reduced dependence on SMS for high-risk authentication workflows.

Get ahead of threats like this
Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
How this story unfolded
1 event from the most recent confirmed update back to the earliest known activity.
Group-IB publishes research on Android SMS stealers targeting Uzbekistan
Group-IB published a report describing a new stage in the evolution of Android SMS-stealing malware in Uzbekistan. The reference indicates ongoing analysis of the threat landscape but provides no earlier discrete events to extract.
Sources
1 reference tracked. Mallory keeps watching after this page renders.
See the full picture, correlated to your attack surface.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.


