Tech

Uzbekistan bank clients have become the target of a new Android virus

Uzbekistan bank clients have become among the targets of a new Android virus

Clients of 12 banks in Uzbekistan have become one of the targets of a new Android malware capable of intercepting SMS, notifications, and other data from infected smartphones. The RedWing Stealer malware is distributed under the guise of VPN services, game modifications, and other applications.

This is stated in a study by the Russian company F6, whose specialists identified more than 800 samples of RedWing Stealer distributed from May to September 2026. In addition to Uzbekistan, the malware targets clients of 16 Russian and seven Kazakhstani banks, as well as a number of marketplaces and microfinance organizations.

F6 does not specify which 12 banks in Uzbekistan are on the target list. The names of the financial organizations are not provided in the published study.

After installation, RedWing Stealer searches the phone for SMS from specific banking senders and transmits them to the attackers. The malware is also capable of reading push notifications, obtaining information about the device, its location, connected SIM cards, call history, contacts, and installed applications.

In addition, the stealer can independently send SMS and USSD requests, open links, and hide its icon. This allows it to run in the background and remain less noticeable to the device owner.

To distribute the malware, attackers use applications that outwardly look like useful services. Among them are programs for viewing photos and videos, as well as cheats and modifications for popular mobile games.

Some of these files are distributed through gaming-themed Telegram channels and other resources from which users download APK files directly. At the same time, after installation, the application may indeed mimic the declared function while simultaneously performing malicious actions in the background.

According to F6, after installation, RedWing Stealer sequentially requests access to SMS, background operation, and autostart. The application may then ask the user to enter a PIN code — the entered data is transmitted to the attackers' server.

Access to SMS and notifications poses a particular risk, as such data can be used to intercept confirmation codes and other information related to banking transactions.

To reduce the risk of infection, specialists recommend not installing APK files from messages in messengers, unverified websites, and other unknown sources. It is also worth carefully checking the permissions that an application requests: for example, an information program should not, without an obvious reason, gain access to SMS, contacts, or Android accessibility features.

If a suspicious application is already installed, it is recommended to delete it, check the permissions granted to it, and scan the device with security software. If there is access to SMS, notifications, or accessibility features, it is advisable to change the passwords of important accounts from another device and check banking transactions. If a card is suspected of being compromised, it should be blocked through the bank.

Earlier, F6 specialists discovered more than 360 fraudulent websites in Uzbekistan, Belarus, and Tajikistan that masquerade as government programs and regional media, promising citizens non-existent payouts.

Cookies on xabarchi

We use cookies to remember your language and theme, and to count how many people are reading right now — that count is anonymous, lasts only while your browser is open, and cannot be tied to you or to another visit. With your permission we also measure how the site is read: Microsoft Clarity, which records page views and on-page interactions, and our own count of returning readers. Nothing that recognises you across visits is measured until you accept.