LukasStefanko's profile picture. Malware Researcher at @ESET
Android security, malware analysis, app vulnerability research
http://t.me/androidMalware

Lukas Stefanko

@LukasStefanko

Malware Researcher at @ESET Android security, malware analysis, app vulnerability research http://t.me/androidMalware

Pinned

Just spotted a little "hello" from the #Crocodilus Android banker devs — they left a message in the logs right after the malware launches. Analysis of Crocodilus: cebrf.knf.gov.pl/images/IKO%20L… New developments: threatfabric.com/blogs/crocodil…


Lukas Stefanko reposted

In regards to "cyber influencers", here is a list of people I think are actually great. However, I am extremely biased toward malware related content and/or low-level programming stuff. Unfortunately, some of the really technical people I like also do not post too often. They…


Lukas Stefanko reposted

NEW OffSec Live Session! Kali NetHunter: Live Podcast (Episode 1) 🐉 Join us for the first episode of our Kali NetHunter Podcast, where we explore the world of mobile and wearable penetration testing. Our guest for this episode is Lukas Stefanko (Mobile Hacker), a respected…

offsectraining's tweet image. NEW OffSec Live Session! Kali NetHunter: Live Podcast (Episode 1) 🐉

Join us for the first episode of our Kali NetHunter Podcast, where we explore the world of mobile and wearable penetration testing.

Our guest for this episode is Lukas Stefanko (Mobile Hacker), a respected…

Lukas Stefanko reposted

#ESETresearch has released its latest APT Activity Report (Apr–Sep 2025): 🇨🇳China-aligned groups targeted Latin America amid US-China tensions. 🇷🇺Russia-aligned groups intensified ops against 🇺🇦Ukraine & 🇪🇺EU states. Full report: web-assets.esetstatic.com/wls/en/papers/…

ESETresearch's tweet image. #ESETresearch has released its latest APT Activity Report (Apr–Sep 2025): 🇨🇳China-aligned groups targeted Latin America amid US-China tensions. 🇷🇺Russia-aligned groups intensified ops against 🇺🇦Ukraine & 🇪🇺EU states. Full report: web-assets.esetstatic.com/wls/en/papers/…

Lukas Stefanko reposted

#ESETresearch identified an active campaign distributing #NGate – Android NFC relay malware used for contactless payment fraud – targeting Brazilian users. It is available for download via fake Google Play sites mimicking 4 major banks and 1 e-commerce app. 1/4

ESETresearch's tweet image. #ESETresearch identified an active campaign distributing #NGate – Android NFC relay malware used for contactless payment fraud – targeting Brazilian users.
It is available for download via fake Google Play sites mimicking 4 major banks and 1 e-commerce app. 1/4

Lukas Stefanko reposted

I'm pleased to announce that @LukasStefanko aka @androidmalware2 will be the very first guest after the showcase attacks on the @kalilinux NetHunter Live Podcast! Join us on 14 November, 11am ET. TBA soon @offsectraining @Re4sonKernel @kimocoder @_elwood_ mobile-hacker.com

yesimxev's tweet image. I'm pleased to announce that @LukasStefanko aka @androidmalware2 will be the very first guest after the showcase attacks on the @kalilinux NetHunter Live Podcast! Join us on 14 November, 11am ET. TBA soon @offsectraining @Re4sonKernel @kimocoder @_elwood_ mobile-hacker.com
yesimxev's tweet image. I'm pleased to announce that @LukasStefanko aka @androidmalware2 will be the very first guest after the showcase attacks on the @kalilinux NetHunter Live Podcast! Join us on 14 November, 11am ET. TBA soon @offsectraining @Re4sonKernel @kimocoder @_elwood_ mobile-hacker.com
yesimxev's tweet image. I'm pleased to announce that @LukasStefanko aka @androidmalware2 will be the very first guest after the showcase attacks on the @kalilinux NetHunter Live Podcast! Join us on 14 November, 11am ET. TBA soon @offsectraining @Re4sonKernel @kimocoder @_elwood_ mobile-hacker.com

Lukas Stefanko reposted

Found Related #spyware #campaign Sample / Domain using @Huntio 9d3ac92937c8986ce55b308c60ae8f9a https://signal-encryption-service[.]ct[.]ws/signsdhfg6aug/signsdhfg6aug/Signal_Encryption_Plugin_V4.7.3.apk @500mk500 @LukasStefanko Ref: x.com/LukasStefanko/…

volrant136's tweet image. Found Related #spyware #campaign Sample / Domain using @Huntio   

9d3ac92937c8986ce55b308c60ae8f9a

https://signal-encryption-service[.]ct[.]ws/signsdhfg6aug/signsdhfg6aug/Signal_Encryption_Plugin_V4.7.3.apk

@500mk500 @LukasStefanko 

Ref: x.com/LukasStefanko/…
volrant136's tweet image. Found Related #spyware #campaign Sample / Domain using @Huntio   

9d3ac92937c8986ce55b308c60ae8f9a

https://signal-encryption-service[.]ct[.]ws/signsdhfg6aug/signsdhfg6aug/Signal_Encryption_Plugin_V4.7.3.apk

@500mk500 @LukasStefanko 

Ref: x.com/LukasStefanko/…
volrant136's tweet image. Found Related #spyware #campaign Sample / Domain using @Huntio   

9d3ac92937c8986ce55b308c60ae8f9a

https://signal-encryption-service[.]ct[.]ws/signsdhfg6aug/signsdhfg6aug/Signal_Encryption_Plugin_V4.7.3.apk

@500mk500 @LukasStefanko 

Ref: x.com/LukasStefanko/…

We identified two campaigns targeting #Android users with previously undocumented spyware impersonating #Signal and #ToTok via deceptive websites welivesecurity.com/en/eset-resear… #ESET #ESETresearch

LukasStefanko's tweet image. We identified two campaigns targeting #Android users with previously undocumented spyware impersonating #Signal and #ToTok via deceptive websites
welivesecurity.com/en/eset-resear…  #ESET #ESETresearch
LukasStefanko's tweet image. We identified two campaigns targeting #Android users with previously undocumented spyware impersonating #Signal and #ToTok via deceptive websites
welivesecurity.com/en/eset-resear…  #ESET #ESETresearch


We identified two campaigns targeting #Android users with previously undocumented spyware impersonating #Signal and #ToTok via deceptive websites welivesecurity.com/en/eset-resear… #ESET #ESETresearch

LukasStefanko's tweet image. We identified two campaigns targeting #Android users with previously undocumented spyware impersonating #Signal and #ToTok via deceptive websites
welivesecurity.com/en/eset-resear…  #ESET #ESETresearch
LukasStefanko's tweet image. We identified two campaigns targeting #Android users with previously undocumented spyware impersonating #Signal and #ToTok via deceptive websites
welivesecurity.com/en/eset-resear…  #ESET #ESETresearch

Lukas Stefanko reposted

#ESETResearch has identified two campaigns targeting Android users in the🇦🇪. The campaigns, which are still ongoing, distribute previously undocumented spyware impersonating #Signal and #ToTok via deceptive websites. welivesecurity.com/en/eset-resear… 1/6


Lukas Stefanko reposted

#ESETResearch has discovered the first known AI-powered ransomware, which we named #PromptLock. The PromptLock malware uses the gpt-oss:20b model from OpenAI locally via the Ollama API to generate malicious Lua scripts on the fly, which it then executes 1/6

ESETresearch's tweet image. #ESETResearch has discovered the first known AI-powered ransomware, which we named #PromptLock. The PromptLock malware uses the gpt-oss:20b model from OpenAI locally via the Ollama API to generate malicious Lua scripts on the fly, which it then executes 1/6

Lukas Stefanko reposted

@LukasStefanko explains why smartphones are the perfect target for digital spies. 🎙️ Listen to Unlocked 403 Podcast now on Spotify, or Apple Podcasts, and stay one step ahead of digital threats. @ESETresearch #Unlocked403


Lukas Stefanko reposted

In H1 2025, #ESETResearch telemetry recorded a 160% surge in #Android adware & clicker detections. Leading this spike is a colorfully branded threat #Kaleidoscope, responsible for 28% of all Android #adware detections in H1. 1/6


Lukas Stefanko reposted

ESET Threat Report H1 2025: #ClickFix attacks surge 500%, SnakeStealer tops infostealer charts, and NFC fraud jumps 35x. Plus, chaos in the ransomware underworld and a new Android adware menace—Kaleidoscope. Dive into the full report: web-assets.esetstatic.com/wls/en/papers/… #ESETresearch

ESETresearch's tweet image. ESET Threat Report H1 2025: #ClickFix attacks surge 500%, SnakeStealer tops infostealer charts, and NFC fraud jumps 35x. Plus, chaos in the ransomware underworld and a new Android adware menace—Kaleidoscope. Dive into the full report: web-assets.esetstatic.com/wls/en/papers/… #ESETresearch

Lukas Stefanko reposted

A Turkish threat actor and Android malware author sent a private message to security researcher Lukas Stefanko. The droppers distributed by these threat actors report victim interactions back to them using log messages in Turkish.

0x6rss's tweet image. A Turkish threat actor and Android malware author sent a private message to security researcher Lukas Stefanko. The droppers distributed by these threat actors report victim interactions back to them using log messages in Turkish.
This post is unavailable.

Lukas Stefanko reposted

Malware #Crocodilus impersonates a fake “IKO Lokata” app — its icon closely resembles that of a major Polish bank 🏦. 📣 Delivered via fake ads on @Facebook. 🔗 Campaign domains: • iko-power-app[.sbs • iko-lokata[.icu 🧠 IoC: rentvillcr[.homes VT: virustotal.com/gui/file/0009a…

karol_paciorek's tweet image. Malware #Crocodilus impersonates a fake “IKO Lokata” app — its icon closely resembles that of a major Polish bank 🏦. 

📣 Delivered via fake ads on @Facebook.

🔗 Campaign domains:
• iko-power-app[.sbs
• iko-lokata[.icu

🧠 IoC: 
rentvillcr[.homes

VT:
virustotal.com/gui/file/0009a…

🚨 Uwaga! Cyberprzestępcy publikują fałszywe reklamy na portalu @facebook, zachęcające do pobrania złośliwej aplikacji na Androida 📱. Malware podszywa się pod rzekomo oficjalną aplikację „IKO Lokata” — która nie istnieje ❗ ⚠️ Po instalacji pobierany jest kolejny złośliwy…

CSIRT_KNF's tweet image. 🚨 Uwaga!
Cyberprzestępcy publikują fałszywe reklamy na portalu @facebook, zachęcające do pobrania złośliwej aplikacji na Androida 📱.

Malware podszywa się pod rzekomo oficjalną aplikację „IKO Lokata” — która nie istnieje ❗

⚠️ Po instalacji pobierany jest kolejny złośliwy…


Lukas Stefanko reposted

#BREAKING #ESETresearch NFC Android malware impersonates banking app in 🇵🇱 Poland. #NGate malware impersonates a banking verification application to steal NFC data and PIN from victims’ physical payment card. @LukasStefanko 1/3

ESETresearch's tweet image. #BREAKING #ESETresearch NFC Android malware impersonates banking app in 🇵🇱 Poland. #NGate malware impersonates a banking verification application to steal NFC data and PIN from victims’ physical payment card. @LukasStefanko 1/3
ESETresearch's tweet image. #BREAKING #ESETresearch NFC Android malware impersonates banking app in 🇵🇱 Poland. #NGate malware impersonates a banking verification application to steal NFC data and PIN from victims’ physical payment card. @LukasStefanko 1/3

Lukas Stefanko reposted

I hacked into the Telegram bot and retrieved all the logs😃. It seems that Spain🇪🇸 is being targeted. @g0njxa 🫣 threat actor: ledear_dev sample: 9dc524efab35e8d79108fa8920119c6e Additionally, telegram vulnerability CVE-2024-7014 has already been fixed.

0x6rss's tweet image. I hacked into the Telegram bot and retrieved all the logs😃. It seems that Spain🇪🇸 is being targeted. 
@g0njxa
 🫣
threat actor: ledear_dev
sample: 9dc524efab35e8d79108fa8920119c6e
Additionally, telegram vulnerability CVE-2024-7014 has already been fixed.
0x6rss's tweet image. I hacked into the Telegram bot and retrieved all the logs😃. It seems that Spain🇪🇸 is being targeted. 
@g0njxa
 🫣
threat actor: ledear_dev
sample: 9dc524efab35e8d79108fa8920119c6e
Additionally, telegram vulnerability CVE-2024-7014 has already been fixed.
0x6rss's tweet image. I hacked into the Telegram bot and retrieved all the logs😃. It seems that Spain🇪🇸 is being targeted. 
@g0njxa
 🫣
threat actor: ledear_dev
sample: 9dc524efab35e8d79108fa8920119c6e
Additionally, telegram vulnerability CVE-2024-7014 has already been fixed.

In the latest version of G-700 Android RAT was allegedly added exploitation of the #EvilVideo Telegram vulnerability (CVE-2024-7014) The exploit allows sending malicious APK files disguised as video EvilVideo: welivesecurity.com/en/eset-resear… G-700 RAT: cyfirma.com/research/g700-…

LukasStefanko's tweet image. In the latest version of G-700 Android RAT was allegedly added exploitation of the #EvilVideo Telegram vulnerability (CVE-2024-7014)

The exploit allows sending malicious APK files disguised as video
EvilVideo: welivesecurity.com/en/eset-resear…
G-700 RAT: cyfirma.com/research/g700-…
LukasStefanko's tweet image. In the latest version of G-700 Android RAT was allegedly added exploitation of the #EvilVideo Telegram vulnerability (CVE-2024-7014)

The exploit allows sending malicious APK files disguised as video
EvilVideo: welivesecurity.com/en/eset-resear…
G-700 RAT: cyfirma.com/research/g700-…
LukasStefanko's tweet image. In the latest version of G-700 Android RAT was allegedly added exploitation of the #EvilVideo Telegram vulnerability (CVE-2024-7014)

The exploit allows sending malicious APK files disguised as video
EvilVideo: welivesecurity.com/en/eset-resear…
G-700 RAT: cyfirma.com/research/g700-…


In the latest version of G-700 Android RAT was allegedly added exploitation of the #EvilVideo Telegram vulnerability (CVE-2024-7014) The exploit allows sending malicious APK files disguised as video EvilVideo: welivesecurity.com/en/eset-resear… G-700 RAT: cyfirma.com/research/g700-…

LukasStefanko's tweet image. In the latest version of G-700 Android RAT was allegedly added exploitation of the #EvilVideo Telegram vulnerability (CVE-2024-7014)

The exploit allows sending malicious APK files disguised as video
EvilVideo: welivesecurity.com/en/eset-resear…
G-700 RAT: cyfirma.com/research/g700-…
LukasStefanko's tweet image. In the latest version of G-700 Android RAT was allegedly added exploitation of the #EvilVideo Telegram vulnerability (CVE-2024-7014)

The exploit allows sending malicious APK files disguised as video
EvilVideo: welivesecurity.com/en/eset-resear…
G-700 RAT: cyfirma.com/research/g700-…
LukasStefanko's tweet image. In the latest version of G-700 Android RAT was allegedly added exploitation of the #EvilVideo Telegram vulnerability (CVE-2024-7014)

The exploit allows sending malicious APK files disguised as video
EvilVideo: welivesecurity.com/en/eset-resear…
G-700 RAT: cyfirma.com/research/g700-…

Lukas Stefanko reposted

Cybercriminals Use NFC Relay to Turn Stolen Credit Cards into Cash without a PIN : mobile-hacker.com/2024/12/02/cyb… credits @LukasStefanko


Loading...

Something went wrong.


Something went wrong.