Ajina

Description

(Group-IB) In May 2024, Group-IB analysts discovered suspicious activity targeting bank customers in the Central Asia region. The threat actors have been spreading malicious Android malware designed to steal users’ personal and banking information, and potentially intercept 2FA messages. During the investigation, Group-IB discovered .APK files masquerading as legitimate applications that facilitated payments, banking, deliveries, and other daily uses. These malicious files were spread across Telegram channels.

Names

Name
Ajina

Category

Malware

Type

  • Banking trojan

Information

Other Information

Uuid

25a15f49-2dd7-4894-b7d9-2e6c3f1456db

Last Card Change

2024-10-23