A newly uncovered Android malware family named Qwizzserial is wreaking havoc across Uzbekistan, stealing sensitive financial data from thousands of mobile users by exploiting the countryβs reliance on SMS-based two-factor authentication (2FA).
Discovered by Group-IB, Qwizzserial represents a new generation of Android malware campaigns where malicious APKs are generated and distributed via Telegram bots, allowing cybercriminals to launch highly scalable and localized attacks.
βThis research uncovers the previously unknown family of Android SMS stealers… named Qwizzserial after the common Java package name for its main activity component,β the report states.
The campaign is hyper-targeted at Uzbek users, where SMS remains the backbone of online financial transactions. With limited adoption of biometric or 3D Secure technologies, most servicesβincluding P2P transfers, mobile payments, and app authorizationsβstill rely on SMS as the only security layer.
βThe implication of the reliance of payment systems on SMS authentication means that fraudsters can intercept the SMS, and give them control over the victimβs finances,β the report warns.
The attackers exploit Telegram channels disguised as official government services, using deceptive APKs titled βAre these your photos?β or βPresidential Supportβ to trick victims into downloading malware under the guise of financial aid.
βThreat actors commonly disguise the malware under deceptive file names… often create Telegram Channels posing as official government entities,β the report explains.
Screenshots from these channels show fake presidential decrees and government assistance formsβcontent designed to build trust and trick citizens into downloading malware-laced apps.
This campaign mimics the Classiscam model, but instead of classic phishing links, it distributes fully weaponized APKs. Telegram bots automate the creation of these fake apps and manage group chats among threat actorsβadmins, βworkers,β card verifiers (βvbiversβ), and fraud trainers.
βTelegram bots play a central role… used to generate the malicious applications and to grant access to internal group chats.β
In just three months, from March to June 2025, a single Qwizzserial gang made over US$62,000, according to figures posted in their own βProfitsβ Telegram channels. The campaign has infected approximately 100,000 devices via more than 1,200 malware variants, many disguised as financial services apps.
Group-IBβs telemetry reveals a daily increase in new samples and notes a Pareto distribution in infection spreadβ25% of samples account for 80% of the infections.
Once installed and granted permissions, Qwizzserial:
- Requests READ/RECEIVE SMS, CALL permissions, and repeats the prompt until granted.
- Prompts users to enter bank card data and phone numbers.
- Steals:
- Full SMS history
- Contact list
- Installed financial apps
- SIM card details
- Device and network metadata
- Uses regex to scan for SMS messages related to account balances or large sums.
- Sends data via Telegram API to fraud team-specific chat rooms.
- In latest versions, switches to exfiltration through an HTTP gate server before forwarding data to Telegram bots.
βAll the data described above is exfiltrated using Telegram bots to four distinct chats, each designated for a specific message type.β
Later variants, like one masked as a βVideoβ app, are now obfuscated using NP Manager and Allatori Demo, with added persistence features like battery optimization disabling, allowing malware to stay active indefinitely.
βThe recent samples also include unused Java packages NPStringFog and NPProtect, suggesting potential future use.β
These versions no longer directly ask for bank card infoβinstead, they rely on SMS-intercepted OTPs to access banking apps silently in the background.
Qwizzserial is a textbook case of how threat actors adapt existing cybercrime-as-a-service (CaaS) models, like Classiscam, for mobile malware deployment. Using Telegram bots for malware automation and localizing the attack for Uzbek victims, the campaign shows how low-cost tools and infrastructure can deliver high-impact financial fraud at scale.
Related Posts:
- Palo Alto Networks’ Unit 42 Reveals a New Cyber Threat in China: Financial Fraud APKs
- Secure Email Gateways Fail to Stop Advanced Phishing Campaign Targeting Multiple Industries
- 184 Million Leaked Credentials Found in Open Database
- Android App Bundles and Dynamic Delivery will customize application packages for different versions of Android
Support Our Threat Intelligence
If you find our CVE report and cybersecurity news helpful, consider supporting our work.