Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Wonderland Android Malware Targets OTPs Through Two-Way SMS Hijacking

Group-IB security researchers have identified a new Android malware family, "Wonderland," representing an advanced evolution in SMS-stealing threats targeting users in Uzbekistan.

Group-IB security researchers have identified a new Android malware family, "Wonderland," representing an advanced evolution in SMS-stealing threats targeting users in Uzbekistan.

Unlike earlier malware versions that used simple one-way data exfiltration, Wonderland employs bidirectional WebSocket-based command-and-control communication. This allows infected devices to act as remotely controlled agents, executing arbitrary commands in real time.

The malware campaign, active since October 2025, indicates a shift in attacker tactics. Threat actors have moved away from direct Trojan distribution to multi-stage infection chains using dropper applications that appear as legitimate software.

These droppers initially seem benign during security scans, with malicious payloads encrypted and stored in the application's assets folder.

Timeline of Android malware evolution in Uzbekistan.

Upon installation, the dropper silently deploys the SMS stealer without needing an internet connection, enhancing infection success rates while avoiding traditional detection mechanisms.

Wonderland's key feature is the use of the WebSocket protocol for real-time C2 communication. Threat actors frequently alter the package names of their malicious applications, sometimes daily, rendering name-based detection ineffective.

This allows infected devices to act as remotely controlled agents, executing arbitrary commands in real time.
Natalie Rhodes · Thehackingpost

Alternative Telegram clients like Graph Messenger play critical roles, offering features such as message forwarding to all contacts and SMS-based authentication to bypass login restrictions.

This architecture enables operators to execute dynamic commands, including arbitrary USSD requests, SMS transmissions, and notification suppression. The command-handling code allows attackers to enable call forwarding dynamically without requiring carrier-specific updates.

The malware includes sophisticated anti-analysis capabilities like emulator detection, root identification, and Frida instrumentation framework detection. If security researchers or sandboxes attempt analysis, Wonderland terminates its activities immediately, preventing behavior observation and network traffic capture.

The codebase uses advanced obfuscation techniques, replacing class and package names with long repetitive character strings, making manual analysis challenging.

Group-IB researchers identified a distributed C2 infrastructure where threat actors require workers to register their own domains via a Telegram bot.

Advertisement

The bot provides nameservers routing traffic to the primary C2 server, creating resilience against takedowns. If authorities seize one domain, only builds associated with that domain become defunct, while the main infrastructure remains operational.

Primary distribution occurs through compromised Telegram accounts acquired from darknet markets. Attackers use stolen sessions to forward malicious APKs to victims' "Saved Messages," creating cyclical infection chains.

Data from tracked cybercriminal Telegram channels reveals a single group generated over $2 million in 2025, demonstrating the significant financial impact of SMS stealer evolution in the region.

Group-IB Fraud Protection has developed detection rules for both dropper and SMS stealer components, with pattern-based identification capable of detecting new samples regardless of delivery method.

Security experts recommend organizations implement comprehensive monitoring strategies, including behavioral detection, application allowlisting, and regular security awareness training focused on recognizing social engineering tactics specific to the Uzbekistan threat landscape.

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories