#Datzbro
-Malware reports on MatrixPDF, XiebroC2, Datzbro RAT, Klopatra banking trojan, GhostSocks
-Iranian port hacking operations
-TikTok info-ops reach Czechia
-New Phantom Taurus APT
-Broadcom patches VMware zero-day
-Supposed SonicWall 2FA bypass campaign
-Made-up Linux vulns
-Preauth vulns in TRUfusion
October 1, 2025 at 8:23 AM
Oplichting via facebookgroepen met activiteiten voor ouderen. Door de app Datzbro te downloaden, kregen oplichters toegang tot inlog- en betalingsgegevens, en maakten camera- en audio-opnamen.

bnr.nl/nieuws/tech-...
Nieuw ‘trojaans paard’ ontdekt gericht tegen ouderen; verspreidt zich in rap tempo over wereld
Onderzoekers van cybersecurity-bedrijf ThreatFabric hebben een wereldwijd oplichtingsnetwerk blootgelegd, genaamd Datzbro. De vrees bestaat dat het netwerk ...
bnr.nl
October 1, 2025 at 12:46 AM
Alert: New Android trojan 'Datzbro' uses AI-generated Facebook events to target elderly users. Stay vigilant and only download apps from trusted sources. #CyberSecurity #AndroidMalware #Datzbro Link: thedailytechfeed.com/emerging-and...
September 30, 2025 at 3:55 PM
New Android Trojan “Datzbro” Tricking Elderly with AI-Generated Facebook Travel Events #cybersecurity #hacking #news #infosec #security #technology #privacy thehackernews.com/20...
September 30, 2025 at 2:14 PM
Criminal Hacker contro Anziani! Arriva Datzbro: Facebook e smartphone nel mirino

📌 Link all'articolo : www.redhotcyber.com/post/cri...

#redhotcyber #hacking #cti #ai #online #it #cybercrime #cybersecurity #technology #news #cyberthreatintelligence #innovation #privacy
October 3, 2025 at 2:51 PM
高齢者を狙った新たな詐欺キャンペーンがFacebookで拡大している。高齢者向けコミュニティイベントの宣伝を装ったFacebookグループから偽サイトにアクセスさせてアプリのダウンロードを促し、マルウェアDatzbroをインストールさせる。 therecord.media/seniors-targ...
Seniors targeted in global Facebook scam spreading new Android malware
The scam originated in Australia in August but has since been seen in several countries around the globe.
therecord.media
October 1, 2025 at 2:46 PM
Datzbro Android Banking Trojan Targets Seniors With Device-Takeover Attacks #Android #AndroidBankingTrojan #AndroidTrojans
Datzbro Android Banking Trojan Targets Seniors With Device-Takeover Attacks
 Researchers have uncovered a previously undocumented Android banking trojan, dubbed Datzbro, that is being used in device-takeover campaigns aimed squarely at older adults. ThreatFabric, a Dutch mobile security firm, first tied the activity to a social-engineering network in August 2025 after reports emerged of Facebook groups in Australia advertising “active senior trips” that were in fact recruitment channels for the scam. The operation has been observed in multiple countries, including Singapore, Malaysia, Canada, South Africa and the U.K., and relies on community-focused messaging to build trust before delivering malware.  The attackers create convincing Facebook groups and AI-generated posts promoting local events for seniors. When a target shows interest, operators move the conversation to Facebook Messenger or WhatsApp and push a link to download a so-called community app—usually an APK hosted on a fraudulent domain. Those sites promise event registration and networking features but deliver an installer that either installs Datzbro directly or drops a secondary loader built with an APK-binding service called Zombinder, which helps bypass protections introduced in Android 13 and later. Some evidence suggests the fraudsters are preparing iOS TestFlight lures as well, indicating cross-platform ambitions.  Analysts have cataloged multiple malicious app package names used to distribute the trojan, from innocuous-sounding “Senior Group” and “Lively Years” to variants masquerading as popular Chinese apps or tools. Once installed, Datzbro grants itself extensive permissions and weaponizes Android accessibility services to perform actions on behalf of the attacker. It can record audio, capture photos, harvest files, log keystrokes and overlay semi-transparent screens to hide malicious activity from victims. A distinctive feature is its “schematic remote control” mode, which reports screen layout, element positions and content back to operators so they can reconstruct interfaces remotely and direct the device as if they were looking over the victim’s shoulder.  The trojan also filters accessibility event logs for bank or wallet package names and scans for text resembling PINs, passwords or transaction codes. If it finds credentials in cookies or other storage, Datzbro exfiltrates them to the attackers’ back end; it can even steal lock-screen PINs and compromise popular Chinese payment apps such as Alipay and WeChat. ThreatFabric noted Chinese debug strings and a Chinese-language desktop command-and-control application tied to the campaign, suggesting the authors are Chinese-speaking. A compiled C2 client reportedly leaked to public malware repositories, which may accelerate wider abuse by other criminals.  Datzbro’s discovery comes amid broader mobile-banking malware activity. IBM X-Force has described a related AntiDot campaign called PhantomCall that similarly abuses Android features and sideloaded droppers to bypass modern OS protections, while PRODAFT has documented MaaS-style offerings for actors aiming at global banks. Together, these trends reflect a sustained move toward targeted social engineering that exploits community trust to coax vulnerable users into installing powerful remote-control malware.  The rapid evolution of these threats underscores the need for heightened public awareness—especially among seniors—tighter app-distribution controls, and stronger defenses around accessibility permissions and sideloaded software.
dlvr.it
October 1, 2025 at 3:33 PM
Threat Actors Leveraging Senior Travel Scams to Deliver Datzbro Malware
Threat Actors Leveraging Senior Travel Scams to Deliver Datzbro Malware
Cybersecurity researchers have uncovered a sophisticated Android malware campaign targeting seniors through fraudulent travel and social activity promotions on Facebook. The newly identified Datzbro malware represents a dangerous evolution in mobile threats, combining advanced spyware capabilities with remote access tools designed to facilitate financial fraud. This campaign, first detected in August 2025, has expanded beyond Australia to target users across Singapore, Malaysia, Canada, South Africa, and the United Kingdom, demonstrating the global reach of these malicious operations. The attack begins with threat actors creating numerous Facebook groups promoting “active senior trips,” dance events, and social gatherings specifically tailored to appeal to older adults seeking community activities. These groups feature sophisticated content generated using artificial intelligence, creating convincing promotional materials that successfully attract genuine interest from potential victims. The consistent appearance and messaging across groups targeting different geographical regions suggests coordination by a single threat actor or organized group operating at scale. Fraudsters operating these groups contact interested victims through private messaging platforms including Facebook Messenger and WhatsApp, where they share links to download specialized applications purportedly required for event registration. ThreatFabric analysts identified this malware distribution mechanism after investigating multiple scam alerts reported across affected regions. The researchers discovered that victims were often asked to pay registration fees through the same malicious websites, creating additional opportunities for credential theft and financial fraud beyond the malware installation. User’s reports online (Source – Threat Fabric) The fake websites employed in these campaigns prompt visitors to install what appears to be a legitimate community application, claiming it enables event registration, member connections, and activity tracking. While the iOS application buttons currently serve as non-functional placeholders, researchers warn these could later be updated to distribute WebClip or TestFlight applications designed to steal credentials and payment information. Fake Facebook senior’s groups (Source – Threat Fabric) However, clicking the Google Play button immediately triggers the download of malicious APK files containing either Datzbro directly or the Zombinder dropper, specifically designed to bypass Android 13+ security restrictions. Advanced Remote Access and Financial Targeting Capabilities Datzbro employs sophisticated remote access technologies that distinguish it from conventional mobile malware families. The malware leverages Android Accessibility Services to execute remote actions on behalf of operators, supporting comprehensive device control including screen sharing, interface interaction, and file management. Each operator command corresponds to specific gestures or system functions, enabling threat actors to simulate button clicks, navigate applications, and perform complex interactions while remaining undetected by victims. The malware’s “schematic” remote control mode represents a particularly innovative approach to device manipulation. This feature creates basic screen layout representations using Accessibility event data, transmitting information about displayed elements, their positions, and content to command and control servers. Operators can recreate the device interface on their systems, enabling effective control even when video streaming quality is poor or when black overlay attacks are active. This dual-control mechanism ensures consistent access regardless of network conditions or defensive countermeasures . Datzbro incorporates advanced evasion techniques including customizable black overlay attacks that hide fraudulent activities from victims. Operators can adjust overlay transparency levels and display custom text messages, creating the impression that devices are idle or experiencing normal system updates. While victims see opaque overlays preventing interaction observation, operators maintain semi-transparent views enabling continued device control. This sophisticated visual deception allows financial transactions and credential harvesting to occur without victim awareness, significantly increasing attack success rates. The malware specifically targets banking and cryptocurrency applications through hardcoded filtering systems that monitor Accessibility events for financial keywords including “bank,” “pay,” “wallet,” and “finance.” Chinese language variants targeting “密码验证” (password verification) and “验证码” (verification code) demonstrate the malware’s multilingual capabilities and global targeting scope. This focused approach to financial application monitoring, combined with keylogging capabilities and credential theft activities, positions Datzbro as a significant banking Trojan capable of comprehensive financial fraud operations against unsuspecting victims worldwide. Follow us on  Google News ,  LinkedIn , and  X  to Get More Instant Updates ,  Set CSN as a Preferred Source in  Google . The post Threat Actors Leveraging Senior Travel Scams to Deliver Datzbro Malware appeared first on Cyber Security News .
cybersecuritynews.com
October 1, 2025 at 8:18 PM
Datzbro: RAT Hiding Behind Senior Travel Scams
Datzbro: RAT Hiding Behind Senior Travel Scams
www.threatfabric.com
October 2, 2025 at 2:09 PM
📢 Datzbro : un nouveau RAT Android ciblant des seniors via de fausses offres de voyage sur Facebook
📝 Selon Threat…
https://cyberveille.ch/posts/2025-09-30-datzbro-un-nouveau-rat-android-ciblant-des-seniors-via-de-fausses-offres-de-voyage-sur-facebook/ #Abus_des_services_d_accessibilité #Cyberveille
October 1, 2025 at 6:00 AM
New Android Trojan “Datzbro” Tricking Elderly with AI-Generated Facebook Travel Events

Cybersecurity researchers have flagged a previously undocumented Android banking trojan called Datzbro that can conduct device takeover (DTO) attacks and perform fraudulent transactions by pre…

#hackernews #news
New Android Trojan “Datzbro” Tricking Elderly with AI-Generated Facebook Travel Events
Cybersecurity researchers have flagged a previously undocumented Android banking trojan called Datzbro that can conduct device takeover (DTO) attacks and perform fraudulent transactions by preying on the elderly. Dutch mobile security company ThreatFabric said it discovered the campaign in August 2025 after users in Australia reported scammers managing Facebook groups promoting "active senior
thehackernews.com
October 1, 2025 at 4:00 AM
Datzbro Android Trojan: A Rising Threat Targeting Seniors Worldwide

The digital world is constantly evolving, but so are the threats lurking in its shadows. A new cybersecurity danger, the Datzbro Android Trojan, has emerged, targeting an often-overlooked demographic: seniors. Disguised as…
Datzbro Android Trojan: A Rising Threat Targeting Seniors Worldwide
The digital world is constantly evolving, but so are the threats lurking in its shadows. A new cybersecurity danger, the Datzbro Android Trojan, has emerged, targeting an often-overlooked demographic: seniors. Disguised as harmless Facebook groups promoting “active senior trips,” this malware is spreading across countries including Australia, Singapore, Malaysia, Canada, South Africa, and the United Kingdom. Its sophisticated capabilities allow cybercriminals to gain full remote control of infected devices, capturing audio and video, logging keystrokes, and even accessing sensitive banking information.
undercodenews.com
October 18, 2025 at 9:49 AM
Datzbro: RAT Hiding Behind Senior Travel Scams https://packetstorm.news/news/view/38972 #news
September 30, 2025 at 6:02 PM
Threat Actors leveraging Senior Travel Scams to deliver Datzbro Malware:

cybersecuritynews.com/threat-actor...
October 2, 2025 at 6:09 AM
Cybersecurity researchers have flagged a previously undocumented Android banking trojan called Datzbro that can conduct device takeover (DTO) attacks and perform fraudulent transactions by preying on the elderly.

thehackernews.com/2025/09/new-...
New Android Trojan “Datzbro” Tricking Elderly with AI-Generated Facebook Travel Events
New Android banking trojan Datzbro targets seniors via fake Facebook groups, enabling device takeover and financial fraud.
thehackernews.com
October 1, 2025 at 5:04 AM
高齢者標的の新型マルウェアDatzbro、AIがFacebookイベントを偽装しAndroid端末を乗っ取り
innovatopia.jp/cyber-securi...

今回のDatzbroマルウェアが示すのは、サイバー犯罪における「標的の精緻化」と「AI技術の悪用」という2つの重要なトレンドです。従来のマルウェアキャンペーンが不特定多数を狙う傾向にあったのに対し、このケースでは高齢者というデジタルリテラシーが比較的低い層に絞り込み、彼らの心理的欲求――つまり社会的つながりや旅行への関心――を巧みに利用しています。
高齢者標的の新型マルウェアDatzbro、AIがFacebookイベントを偽装しAndroid端末を乗っ取り
オランダのモバイルセキュリティ企業ThreatFabricは、2025年8月にAndroidバンキング型トロイ
innovatopia.jp
October 2, 2025 at 2:36 AM
New Android Trojan "Datzbro" Tricking Elderly with AI-Generated Facebook Travel Events thehackernews.com/2025/09/new-...
New Android Trojan “Datzbro” Tricking Elderly with AI-Generated Facebook Travel Events
New Android banking trojan Datzbro targets seniors via fake Facebook groups, enabling device takeover and financial fraud.
thehackernews.com
September 30, 2025 at 11:50 AM
New Android Trojan “Datzbro” Tricking Elderly with AI-Generated Facebook Travel Events

Cybersecurity researchers have flagged a previously undocumented Android banking trojan called Datzbro that can conduct device takeover (DTO) attacks and perform fraudulent transactions by preying on the…
New Android Trojan “Datzbro” Tricking Elderly with AI-Generated Facebook Travel Events
Cybersecurity researchers have flagged a previously undocumented Android banking trojan called Datzbro that can conduct device takeover (DTO) attacks and perform fraudulent transactions by preying on the elderly. Dutch mobile security company ThreatFabric said it discovered the campaign in August 2025 after users in Australia reported scammers managing Facebook groups promoting "active senior
thehackernews.com
September 30, 2025 at 10:17 AM
📌 New Android Trojan Datzbro Targets Elderly Australians via AI-Generated Facebook Scams https://www.cyberhub.blog/article/13840-new-android-trojan-datzbro-targets-elderly-australians-via-ai-generated-facebook-scams
New Android Trojan Datzbro Targets Elderly Australians via AI-Generated Facebook Scams
A new Android Trojan named Datzbro has been discovered by ThreatFabric in August 2025. This malware targets elderly people in Australia through AI-generated travel event groups on Facebook. Datzbro is capable of performing device takeover (DTO) attacks and carrying out fraudulent transactions. The use of AI-generated content in social engineering attacks highlights the increasing sophistication of such threats. The targeting of elderly individuals underscores the need for user education and robust security measures. Cybersecurity professionals should be aware of this trend and implement advanced monitoring and detection systems to mitigate the risks associated with Datzbro and similar malware. The financial implications of this malware are significant, as it can lead to substantial financial losses for victims. Organizations should focus on educating users about the risks of social engineering attacks and ensuring that devices are secured with regular updates, antivirus software, and multi-factor authentication. Continuous monitoring for unusual activities is also crucial to detect and mitigate such threats.
www.cyberhub.blog
October 1, 2025 at 5:20 AM