Frogblight banking Trojan targets Android users in Turkey

Dec. 21, 2025, 7:03 p.m.

Description

A new Android banking Trojan called Frogblight has been discovered targeting users in Turkey. Initially disguised as an app for accessing court case files, it later adopted more universal disguises like the Chrome browser. Frogblight can steal banking credentials through official government websites and has spyware capabilities to collect SMS messages, app lists, and device information. It can also send arbitrary SMS messages. The malware has been actively updated with new features, indicating ongoing development. Distribution likely occurs through smishing attacks convincing users they are involved in court cases. Frogblight uses sophisticated techniques for remote device control, persistence, and protection against deletion. The majority of victims are located in Turkey, and the developers likely speak Turkish.

Date

  • Created: Dec. 15, 2025, 1 p.m.
  • Published: Dec. 15, 2025, 1 p.m.
  • Modified: Dec. 21, 2025, 7:03 p.m.

Indicators

  • fe36420caa309941dcd8ec2fab4da905b185b8fdad86d9383dcb46c859f66454
  • e2b6283cb8878fdbb9d6a49b0c77fd2e6a116cf4b1d3ff67a0b0287946d1d865
  • b50888244a4e71f049d6807658860447715e0dc1367bf90f48514e090dcc9fad
  • c9962e1f58876a9b9cae3b4bf52af3466141ecf16601f9b0558410232fc08207
  • 0ebac21f450785766437e4e5dcda121817b198786876744a52cba0627babd1a9
  • 49172f48e354316d1db787a1df1955197e64664b4ed695ed8b5b4491e3167688

Additional Informations

  • Finance
  • trojan-spy.androidos.smsthief.de
  • e-ifade-app-5gheb8jc.devinapps.com
  • farketmez37.cfd
  • froglive.net
  • farketmez36.sbs