CyberHappenings logo

Track cybersecurity events as they unfold. Sourced timelines, daily updates. Fast, privacy‑respecting. No ads, no tracking.

Datzbro Android Trojan Targeting Elderly via AI-Generated Facebook Events

First reported
Last updated
1 unique sources, 1 articles

Summary

Hide ▲

A new Android banking trojan named Datzbro is targeting elderly users through AI-generated Facebook events. The malware, discovered in August 2025, conducts device takeover (DTO) attacks and performs fraudulent transactions. It exploits social engineering tactics to trick victims into downloading malicious APK files from fraudulent links. The threat actors behind Datzbro focus on users in Australia, Singapore, Malaysia, Canada, South Africa, and the U.K. The malware leverages Android's accessibility services to perform remote actions, record audio, capture photos, and steal credentials. It also includes features to hide malicious activities and steal device lock screen PINs and passwords associated with Alipay and WeChat. Datzbro is believed to be the work of a Chinese-speaking threat group, with its command-and-control (C2) backend being a Chinese-language desktop application. The malware has been distributed freely among cybercriminals after a compiled version of the C2 app was leaked.

Timeline

  1. 30.09.2025 12:20 1 articles · 7h ago

    Datzbro Android Trojan Targeting Elderly via AI-Generated Facebook Events

    A new Android banking trojan named Datzbro was discovered in August 2025. It targets elderly users through AI-generated Facebook events, conducting device takeover attacks and performing fraudulent transactions. The malware exploits social engineering tactics to trick victims into downloading malicious APK files. It leverages Android's accessibility services to perform remote actions, record audio, capture photos, and steal credentials. Datzbro is believed to be the work of a Chinese-speaking threat group, with its command-and-control backend being a Chinese-language desktop application. The malware has been distributed freely among cybercriminals after a compiled version of the C2 app was leaked.

    Show sources

Information Snippets