New Wonderland Android Malware with Bidirectional SMS-Stealing Capabilities Stealing OTPs
A new Android malware family named Wonderland has been identified as a threat to users in Uzbekistan and the broader Central Asia region.
A new Android malware family named Wonderland has been identified as a threat to users in Uzbekistan and the broader Central Asia region.
This malware specializes in intercepting SMS messages and one-time passwords (OTPs), posing a significant risk to financial systems.
First detected in October 2025, Wonderland demonstrates advanced technical capabilities compared to previous malware variants in the region.
The malware employs a multi-stage infection process beginning with dropper applications that appear as legitimate software or media files.
The dropper silently extracts and installs the SMS-stealing payload. It uses advanced evasion techniques to avoid detection by security mechanisms. The malware terminates itself when running on emulators, rooted devices, or sandboxed environments. Heavy code obfuscation is utilized to hinder reverse engineering efforts.
A new Android malware family named Wonderland has been identified as a threat to users in Uzbekistan and the broader Central Asia region.
Research by Group-IB indicates that Wonderland is the first mass-spreading Android SMS stealer in Uzbekistan supporting bidirectional command-and-control communication via the WebSocket protocol.
Bidirectional Command and Control Mechanism
The malware can receive real-time commands from attackers, allowing dynamic execution of harmful actions.
Supports arbitrary USSD requests for carrier-specific code manipulation. Enables call forwarding and advanced fraud techniques. Sends arbitrary SMS messages and suppresses push notifications. Maintains persistent communication through a WebSocket connection.
Commands are processed through a handler, executing corresponding operations on compromised devices. Code obfuscation complicates the identification of command handlers.
Group-IB's findings indicate that operators of the malware earned over $2 million in 2025, highlighting its significant impact.
Wonderland is primarily distributed through Telegram, using social engineering to deceive users. Organizations and individuals are advised to enhance security monitoring and avoid installing applications from untrusted sources to mitigate risks.
Based on reporting by Cyber Security News.
