HomeSecuritydeVixor: New Android banking malware

deVixor: New Android banking malware

A new Android banking malware, dubbed deVixor, has emerged, putting users in certain regions at risk. The malware goes beyond simple credential theft; it combines data theft, device control, and extortion, creating a complete platform for criminal activity.

deVixor banking malware

Since October 2025, security researchers have identified over 700 samples of deVixor, indicative of an active and constantly evolving campaign with frequent updates and new capabilities.

Distribution Strategy: Fraudulent Websites and APKs

The distribution of deVixor relies on fake websites that imitate well-known car manufacturers. These pages lure victims with unrealistic offers and discounts on vehicles, encouraging them to install a malicious APK file. Once the file is installed, the malware authenticates the device and begins its malicious activities.

See also: VoidLink: New malware framework targets Linux systems

The attackers manage this operation via Telegram, allowing them to centrally control hundreds of infected devices simultaneously, with each device having a unique identifier for monitoring and sending commands.

deVixor: New Android banking malware

Dual Server Architecture for Security and Flexibility

deVixor uses two separate server systems for communication:

  • Firebase: Handles incoming commands from attackers.
  • Control Server: Receives the stolen data.

This dual-server architecture allows attackers to maintain operational security and adapt to any security intervention. Cyble analysts point out that each new version of deVixor introduces improved evasion and data collection capabilities .

deVixor: Stealing Banking Credentials via SMS

The main goal of deVixor is to steal financial information. The malware scans thousands of SMS messages on infected devices, looking for banking data, one-time passwords, and card numbers.

See also: SHADOW#REACTOR: New campaign distributes Remcos RAT

Specifically, it targets more than 20 banks and cryptocurrency platforms, including Bank Melli Iran, Bank Mellat, Binance, and Ramzinex. The attackers use JavaScript injection via WebView, creating fake banking notifications that record every keystroke the user makes and send the data directly to the attackers.

Ransomware Extortion

One of the most dangerous features of deVixor is its built-in ransomware module. Once it receives the command, the malware locks the device’s and demands a payment in TRON (50 TRX) to unlock the device.

Screenshots from the attackers' Telegram channel show successful device locks, indicating that this extortion tactic is being actively implemented.

See also: ValleyRAT_S2 attacks organizations to install malware

deVixor: New Android banking malware

The evolution of Android malware

deVixor demonstrates how modern Android attacks have transformed from simple credential stealers to full-fledged criminal platforms. It supports multiple attack vectors, constant victim monitoring, and real-time financial extortion.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

For users, prevention is critical: keeping Android updated, avoiding APKs from untrusted sources, using multiple layers of authentication, and paying attention to fake alerts are key protection practices.

Banks and cryptocurrency platforms are urged to strengthen detection of unauthorized access, educate users about phishing attacks, and use transaction monitoring mechanisms to identify suspicious activity.

deVixor highlights the continuous escalation of Android attacks and the importance of proactive security for mobile devices, especially when they are used for banking and cryptocurrency transactions.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS