DiscoverCYFIRMA ResearchCYFIRMA Research- Lazarus Stealer
CYFIRMA Research- Lazarus Stealer

CYFIRMA Research- Lazarus Stealer

Update: 2025-08-29
Share

Description

CYFIRMA research exposes Lazarus Stealer — a stealthy Android banking malware targeting Russian financial institutions.

 Key Attack Vectors:

  • Overlay Attack: Displays fake banking login screens to steal card details & account credentials.
  • Silent SMS Notification Blocking: Obtains default SMS handler rights to suppress OTP alerts from the victim’s view.
  • Real-Time OTP Harvesting: Captures verification codes instantly to bypass multi-factor authentication.
  • Covert C2 Communication: Sends stolen data to attacker-controlled servers.

Link to the Research Report: https://www.cyfirma.com/research/lazarus-stealer-android-malware-for-russian-bank-credential-theft-through-overlay-and-sms-manipulation/

#AndroidMalware #BankingTrojan #OverlayAttack #SMSInterception #OTPTheft #CyberThreatIntel #MobileSecurity #CYFIRMAResearch #CYFIRMA #ETLM #ExternalThreatLandscapeManagement 

https://www.cyfirma.com/

Comments 
In Channel
loading
00:00
00:00
x

0.5x

0.8x

1.0x

1.25x

1.5x

2.0x

3.0x

Sleep Timer

Off

End of Episode

5 Minutes

10 Minutes

15 Minutes

30 Minutes

45 Minutes

60 Minutes

120 Minutes

CYFIRMA Research- Lazarus Stealer

CYFIRMA Research- Lazarus Stealer

CYFIRMA