Cybercriminals have been observed using malicious dropper apps that mimic legitimate apps to distribute an Android SMS stealer called Wonderland. The attacks primarily target users in Uzbekistan.

“ Previously, users received ‘pure’ Trojan APKs that acted as malware immediately upon installation ,” Group -IB said in an analysis published last week. “ Now, adversaries are increasingly using droppers that masquerade as legitimate applications. The dropper appears harmless on the surface, but contains an embedded malicious payload, which is deployed locally upon installation – even without an active internet connection .”
Wonderland (formerly WretchedCat), according to the cybersecurity firm, facilitates two-way command and control (C2) communication to execute commands in real time, allowing arbitrary USSD requests and SMS theft. It disguises itself as Google Play or files in other formats, such as videos, photos and wedding invitations.
See also: Iranian Prince of Persia hackers target critical infrastructure
TrickyWonders: The team behind the Wonderland malware
The financially motivated malicious actor behind the malware, TrickyWonders, uses Telegram as the main platform to coordinate various aspects of the operation. It was first discovered in November 2023 and has been linked to two other dropper malware designed to hide the main encrypted payload: MidnightDat (first seen on August 27, 2025) and RoundRift (first seen on October 15, 2025).
Wonderland is primarily spread through fake Google Play Store websites, Facebook ad campaigns, fake accounts on dating apps , and messaging apps like Telegram. Attackers often exploit stolen Telegram sessions of Uzbek users, which are sold on dark web marketplaces, to distribute APK files to victims' contacts and chats.

How does malware work?
Once the malware is installed, it gains access to SMS messages and steals one-time passwords (OTPs), which the group uses to extort money from victims’ bank cards. Other capabilities include retrieving phone numbers, extracting contact lists, hiding push notifications to suppress security alerts or OTPs, and even sending SMS messages from infected devices for lateral movement.
However, it is worth noting that installing the app first requires users to enable a setting that allows installation from unknown sources. This is accomplished by displaying an update screen that instructs them to “install the update to use the app.”
“When a victim installs the APK and grants permissions, the attackers hijack the phone number and attempt to log in to the Telegram account registered with that phone number,” Group-IB said. “If the connection is successful, the distribution process is repeated, creating a circular infection chain.”
See also: The rise of North Korean hackers: $2 billion in cryptocurrencies stolen
Wonderland represents the latest evolution of mobile malware in Uzbekistan, which has shifted from primitive malware like Ajina.Banker to more covert forms like Qwizzserial.
The use of dropper applications is strategic as it allows them to appear harmless and evade security checks. Furthermore, both the dropper and SMS stealer components are heavily disguised and incorporate anti-analysis tricks to make reverse engineering much more difficult and time-consuming.
Furthermore, the use communication C2 transforms the malware from a passive SMS thief to an active remote control agent that can execute arbitrary USSD requests issued by the server.
“The supporting infrastructure has also become more dynamic and resilient,” the researchers said. “Operators rely on rapidly changing domains, each of which is used only for a limited set of constructs before being replaced. This approach complicates monitoring, defenses blacklist-based increases the lifetime of command and control channels.”
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

The malicious APK builds are created using a special Telegram bot, which is then distributed by a class of attackers, called workers, in exchange for a share of the stolen funds. As part of this effort, each build is associated with its own C2 domains, so that any attempt to take them down does not destroy the entire attack infrastructure.
See also: Nigeria: RaccoonO365 developer arrested
The criminal enterprise also includes group owners, developers, and vbivers, who validate stolen card details. This hierarchical structure reflects a new maturity of the financial fraud enterprise.
“The new wave of malware development in the region clearly demonstrates that methods of compromising Android devices are not just becoming more sophisticated – they are evolving at a rapid pace,” Group-IB said. “Attackers are actively adapting their tools, implementing new approaches to distribution, hiding activity, and maintaining control of infected devices.”
