Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Android Malware Poses Threat to Mobile Banking Users

Android Malware Poses Threat to Mobile Banking Users

Posted on February 19, 2026 By CWS

Cybersecurity experts have identified a new Android malware, dubbed Massiv, which poses a significant threat to mobile banking users. According to ThreatFabric, this malware disguises itself as benign IPTV applications, targeting users interested in online TV services. Its primary objective is to execute device takeover (DTO) attacks for financial theft.

Malware Capabilities and Methods

Massiv is equipped with several features that aid in stealing user credentials. It employs screen streaming, keylogging, SMS interception, and deceptive overlays on banking apps to gather sensitive information. One particular campaign has been found targeting a Portuguese public administration application, tricking users into divulging their phone numbers and PIN codes to bypass Know Your Customer (KYC) processes.

The malware allows operators to control infected devices remotely, perform fraudulent transactions, and create new banking accounts under the victim’s name. It also uses Android’s accessibility services to operate stealthily, displaying a black screen overlay to hide its activities. Techniques similar to those used by other Android banking malware, such as Crocodilus and Klopatra, have been observed.

Technical Exploits and Distribution

The malware exploits Android’s features to capture screen content while circumventing protections against screen capture. It uses a UI-tree mode to process visible UI elements and export them to attackers, who can then interact with the device based on this information. Massiv enables actions such as muting device sounds, altering clipboard contents, and manipulating screen settings.

Massiv is distributed through SMS phishing campaigns, masquerading as IPTV apps. Once installed, it prompts users to allow software installation from external sources under the guise of an essential update. The dropper apps, such as IPTV24 and Google Play, facilitate the installation of the malware on the device.

Impact and Future Developments

Recent campaigns using TV-themed droppers have primarily affected users in Spain, Portugal, France, and Turkey. Although Massiv is not yet marketed as Malware-as-a-Service, its operators show signs of heading in that direction, with ongoing development and potential new features.

This development underscores the persistent demand for advanced malware solutions among cybercriminals. As Massiv continues to evolve, it is crucial for users to remain vigilant and for the cybersecurity community to enhance protective measures against such threats.

The Hacker News Tags:Android malware, banking trojan, credential theft, Cybersecurity, device takeover, IPTV apps, Massiv malware, mobile security, phishing attacks, ThreatFabric

Post navigation

Previous Post: Microsoft Defender Boosts Threat Response with New Script Library
Next Post: OpenClaw Faces Ongoing Security Challenges with New Open Source Tool

Related Posts

Astaroth Banking Trojan Abuses GitHub to Remain Operational After Takedowns Astaroth Banking Trojan Abuses GitHub to Remain Operational After Takedowns The Hacker News
Chaos Mesh Critical GraphQL Flaws Enable RCE and Full Kubernetes Cluster Takeover Chaos Mesh Critical GraphQL Flaws Enable RCE and Full Kubernetes Cluster Takeover The Hacker News
Russian APT28 Deploys “NotDoor” Outlook Backdoor Against Companies in NATO Countries Russian APT28 Deploys “NotDoor” Outlook Backdoor Against Companies in NATO Countries The Hacker News
Researchers Capture Lazarus APT’s Remote-Worker Scheme Live on Camera Researchers Capture Lazarus APT’s Remote-Worker Scheme Live on Camera The Hacker News
AI Aids Discovery of Linux Kernel Vulnerability Exploit AI Aids Discovery of Linux Kernel Vulnerability Exploit The Hacker News
React2Shell Exploitation Delivers Crypto Miners and New Malware Across Multiple Sectors React2Shell Exploitation Delivers Crypto Miners and New Malware Across Multiple Sectors The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Red Hat Kubernetes Vulnerability Risks Internal Services
  • Atlassian and Splunk Address Critical Software Vulnerabilities
  • Critical Isolated-vm Flaw Threatens JavaScript Security
  • OpenAI Pauses AI Training Over Cybersecurity Concerns
  • Massive Camera Hack Hits 14,000 Devices in Ukraine and Russia

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Red Hat Kubernetes Vulnerability Risks Internal Services
  • Atlassian and Splunk Address Critical Software Vulnerabilities
  • Critical Isolated-vm Flaw Threatens JavaScript Security
  • OpenAI Pauses AI Training Over Cybersecurity Concerns
  • Massive Camera Hack Hits 14,000 Devices in Ukraine and Russia

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark