Android Banking Trojan Linked to Cambodia Scam Compounds Hits 21 Countries
2026-04-10T20:51:49Z•42eb8267810502080c25340ba5adb64d7332142f752cd16348bbb1901a144da4
adobe reader zero-dayandroid banking trojancambodia scamclaude-code bypassclaude.mdcrypto wallet theftdns hijackfake-llcforced labourforest blizzard','operation masquerade','fbi doj','russian gru']githubgraphalgolazarusmacos malwaremalicious pdfsmedusa ransomwarenotnullOSXokta phishingrapid-exploitrouter hijackingsocial engineeringsql injectionstorm-1175typo-squattingunc6783
What happened
Multiple active cyber campaigns and high-impact threats reported: an Android banking trojan tied to a Cambodia scam ring (using forced labour) is targeting users across 21 countries to bypass security and steal funds; North Korean Lazarus actors resumed the GraphAlgo campaign by registering realistic US LLCs, typo-squatting on GitHub and posing as SWFT Blockchain to distribute malware to developers; UNC6783 operators are using social engineering and fake Okta login/support pages to breach corporate environments and exfiltrate data; an Adobe Reader zero-day is being actively exploited via malic
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- hackread
- Record identifier
- 42eb8267810502080c25340ba5adb64d7332142f752cd16348bbb1901a144da4
- Enrichment time
- 2026-04-10T20:51:49Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.