Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Android Banking Malware deVixor Actively Targeting Users with Ransomware Capabilities

Android Banking Malware deVixor Actively Targeting Users with Ransomware Capabilities

Posted on January 13, 2026January 14, 2026 By CWS

A complicated Android banking menace has emerged within the menace panorama, posing severe dangers to cell customers throughout sure areas.

The malware, generally known as deVixor, represents a major evolution in Android-based assaults, combining monetary information theft, system management, and extortion inside a single platform.

Since October 2025, safety researchers have recognized over 700 samples of this menace, indicating an lively and ongoing marketing campaign that continues to develop new capabilities.

deVixor operates by a well-coordinated distribution technique, utilizing fraudulent web sites that impersonate professional automotive corporations.

These faux websites appeal to victims with unrealistic car reductions, encouraging them to obtain a malicious APK file. As soon as put in, the malware establishes a foothold on the system and begins its malicious operations.

The menace actors handle this operation by Telegram-based infrastructure, permitting them to take care of centralized management and push updates quickly.

Preliminary model announcement of deVixor RAT (Supply – Cyble)

This strategy allows them to handle a whole lot of contaminated units concurrently, every assigned a singular identifier for monitoring and command supply.

The assault operates utilizing two distinct server programs for communication. Firebase handles incoming instructions from the menace actors, whereas a separate command-and-control server receives stolen information.

deVixor RAT updates in Telegram Group (Supply – Cyble)

This dual-server structure supplies flexibility and helps the attackers keep operational safety.

Cyble analysts famous that the malware reveals clear proof of steady growth, with every new model introducing enhanced capabilities and refined evasion strategies.

Banking Credential Harvesting Via SMS Interception

The first goal of deVixor includes stealing monetary info by SMS message evaluation. The malware scans 1000’s of SMS messages on contaminated units, looking for banking-related content material.

It makes use of common expressions to extract account balances, one-time passwords, and card numbers from messages originating from Iranian banks and cryptocurrency exchanges.

Prompting to grant permissions (Supply – Cyble)

The malware particularly targets over 20 main monetary establishments, together with Financial institution Melli Iran, Financial institution Mellat, and quite a few cryptocurrency platforms like Binance and Ramzinex.

The credential harvesting mechanism operates by WebView-based JavaScript injection. When a sufferer receives a faux financial institution notification, tapping it opens a malicious web page that mimics professional banking interfaces.

The injected JavaScript captures every thing the person varieties, together with login credentials and account info, transmitting this information on to attackers.

A very regarding characteristic includes the embedded ransomware module. Upon receiving the ransomware command, the malware locks the system show and calls for fee in TRON cryptocurrency (50 TRX).

Gathering SMSes coming from banks (Supply – Cyble)

The ransom message shows the attacker’s pockets tackle, and the system stays locked till fee is obtained.

Screenshots from the menace actor’s Telegram channel exhibit profitable system lockings, indicating that this extortion tactic is actively being deployed in opposition to victims.

The technical sophistication of deVixor demonstrates how fashionable Android banking malware has advanced from easy credential stealers into complete legal platforms supporting a number of assault vectors, persistent surveillance, and monetary extortion capabilities focusing on customers worldwide.

Observe us on Google Information, LinkedIn, and X to Get Extra Instantaneous Updates, Set CSN as a Most well-liked Supply in Google.

Cyber Security News Tags:Actively, Android, Banking, Capabilities, deVixor, Malware, Ransomware, Targeting, Users

Post navigation

Previous Post: Broadcom Wi-Fi Chipset Flaw Allows Hackers to Disrupt Networks
Next Post: Critical OpenSSH Vulnerability Exposes Moxa Ethernet Switches to Remote Code Execution

Related Posts

Lenovo IdeaCentre and Yoga Laptop BIOS Vulnerabilities Execute Arbitrary Code Lenovo IdeaCentre and Yoga Laptop BIOS Vulnerabilities Execute Arbitrary Code Cyber Security News
Chrome Security Update – Patch for 21 Vulnerabilities that Allows Attackers to Crash Browser Chrome Security Update – Patch for 21 Vulnerabilities that Allows Attackers to Crash Browser Cyber Security News
Storm-0900 Hackers Leveraging Parking Ticket and Medical Test Themes in Massive Phishing Attack Storm-0900 Hackers Leveraging Parking Ticket and Medical Test Themes in Massive Phishing Attack Cyber Security News
Huge Wave of Malicious Efimer Malicious Script Attack Users via WordPress Sites, Malicious Torrents, and Email Huge Wave of Malicious Efimer Malicious Script Attack Users via WordPress Sites, Malicious Torrents, and Email Cyber Security News
CISA Releases Guide to Protect Network Edge Devices From Hackers CISA Releases Guide to Protect Network Edge Devices From Hackers Cyber Security News
Microsoft Defender for Office 365 to Block Email Bombing Attacks Microsoft Defender for Office 365 to Block Email Bombing Attacks Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Muddled Libra Exploits VMware vSphere in Cyber Attack
  • Feiniu NAS Devices Targeted in Major Botnet Attack
  • Rapid SSH Worm Exploits Linux Systems with Credential Stuffing
  • Odido Telecom Hacked: 6.2 Million Accounts Compromised
  • Lazarus Group Targets npm and PyPI with Malicious Packages

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Muddled Libra Exploits VMware vSphere in Cyber Attack
  • Feiniu NAS Devices Targeted in Major Botnet Attack
  • Rapid SSH Worm Exploits Linux Systems with Credential Stuffing
  • Odido Telecom Hacked: 6.2 Million Accounts Compromised
  • Lazarus Group Targets npm and PyPI with Malicious Packages

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News