Android Banking Trojan Linked to Cambodia Scam Compounds Hits 21 Countries

2026-04-10T20:51:49Z42eb8267810502080c25340ba5adb64d7332142f752cd16348bbb1901a144da4
adobe reader zero-dayandroid banking trojancambodia scamclaude-code bypassclaude.mdcrypto wallet theftdns hijackfake-llcforced labourforest blizzard','operation masquerade','fbi doj','russian gru']githubgraphalgolazarusmacos malwaremalicious pdfsmedusa ransomwarenotnullOSXokta phishingrapid-exploitrouter hijackingsocial engineeringsql injectionstorm-1175typo-squattingunc6783

What happened

Multiple active cyber campaigns and high-impact threats reported: an Android banking trojan tied to a Cambodia scam ring (using forced labour) is targeting users across 21 countries to bypass security and steal funds; North Korean Lazarus actors resumed the GraphAlgo campaign by registering realistic US LLCs, typo-squatting on GitHub and posing as SWFT Blockchain to distribute malware to developers; UNC6783 operators are using social engineering and fake Okta login/support pages to breach corporate environments and exfiltrate data; an Adobe Reader zero-day is being actively exploited via malic

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
hackread
Record identifier
42eb8267810502080c25340ba5adb64d7332142f752cd16348bbb1901a144da4
Enrichment time
2026-04-10T20:51:49Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.