Android malware targeted at Iranian banks has heightened its evasion tactics, according to Zimperium. The campaign has seen over 200 malicious apps connected to the operation, involving phishing attacks on the targeted institutions. Aimed at gathering banking login credentials and credit card details, the apps trick victims into allocating wide-ranging permissions. The campaign could expand to include Apple’s iOS system, as phishing sites authenticate if the page is opened by an iOS device.

“PupkinStealer” A New .NET-Based Malware Steals Browser Credentials & Exfiltrate via Telegram
PupkinStealer is a C# malware that steals sensitive data, including browser credentials and desktop files, using Telegram for stealthy data exfiltration. Discovered in April 2025,