By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
World of SoftwareWorld of SoftwareWorld of Software
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Search
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
Reading: Fake IPTV Apps Spread Massiv Android Malware Targeting Mobile Banking Users
Share
Sign In
Notification Show More
Font ResizerAa
World of SoftwareWorld of Software
Font ResizerAa
  • Software
  • Mobile
  • Computing
  • Gadget
  • Gaming
  • Videos
Search
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Have an existing account? Sign In
Follow US
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
World of Software > Computing > Fake IPTV Apps Spread Massiv Android Malware Targeting Mobile Banking Users
Computing

Fake IPTV Apps Spread Massiv Android Malware Targeting Mobile Banking Users

News Room
Last updated: 2026/02/19 at 5:25 AM
News Room Published 19 February 2026
Share
Fake IPTV Apps Spread Massiv Android Malware Targeting Mobile Banking Users
SHARE

Ravie LakshmananFeb 19, 2026Banking Malware / Mobile Security

Cybersecurity researchers have disclosed details of a new Android trojan called Massiv that’s designed to facilitate device takeover (DTO) attacks for financial theft.

The malware, according to ThreatFabric, masquerades as seemingly harmless IPTV apps to deceive victims, indicating that the activity is primarily singling out users looking for the online TV applications.

“This new threat, while only seen in a limited number of rather targeted campaigns, already poses a great risk to the users of mobile banking, allowing its operators to remotely control infected devices and perform device takeover attacks with further fraudulent transactions performed from the victim’s banking accounts,” the Dutch mobile security company said in a report shared with The Hacker News.

Like various Android banking malware families, Massiv supports a wide range of features to facilitate credential theft through a number of methods: screen streaming through Android’s MediaProjection API, keylogging, SMS interception, and fake overlays served atop banking and financial apps. The overlay asks users to enter their credentials and credit card details.

One such campaign has been found to target gov.pt, a Portuguese public administration app that allows users to store identification documents and manage the Digital Mobile Key (aka Chave Móvel Digital or CMD). The overlay tricks users into entering their phone number and PIN code, likely in an effort to bypass Know Your Customer (KYC) verification.

ThreatFabric said it identified cases where scammers used the information captured through these overlays to open new banking accounts in the victim’s name, allowing them to be used for money laundering or getting loans approved without the actual victim’s knowledge.

In addition, it serves as a fully functional remote-control tool, granting the operator the ability to access the victim’s device stealthily while showing a black screen overlay to conceal the malicious activity. These techniques, realized by abusing Android’s accessibility services, have also been observed in several other Android bankers like Crocodilus, Datzbro, and Klopatra.

“However, some applications implement protection against screen capture,” the company explained. “To bypass it, Massiv uses so-called UI-tree mode — it traverses AccessibilityWindowInfo roots and recursively processes AccessibilityNodeInfo objects.”

This is done so as to build a JSON representation of visible text and content descriptions, UI elements, screen coordinates, and interaction flags that indicate whether the UI element is clickable, editable, focused, or enabled. Only nodes that are visible and have text are exported to the attacker, who can then determine the next course of action by issuing specific commands to interact with the device.

The malware is equipped to carry out a wide range of malicious actions –

  • Enable black overlay, mute sounds and vibration
  • Send device information
  • Perform click and swipe actions
  • Alter clipboard with specific text
  • Disable black screen
  • Turn on/off screen streaming
  • Unlock device with pattern
  • Serve overlays for an app, device pattern lock, or PIN
  • Download ZIP archive with overlays for targeted applications
  • Download and install APK files
  • Open Battery Optimization, Device Admin, and Play Protect settings screens
  • Rquest for permissions to access SMS messages, install APK packages, 
  • Clear log databases on the device

Massiv is distributed in the form of dropper apps mimicking IPTV apps via SMS phishing. Once installed and launched, the dropper prompts the victim to install an “important” update by granting it permissions to install software from external sources. The names of the malicious artifacts are listed below –

  • IPTV24 (hfgx.mqfy.fejku) – Dropper
  • Google Play (hobfjp.anrxf.cucm) – Massiv

“In most of the cases observed, it is just masquerading,” ThreatFabric said. “No actual IPTV applications were infected or initially contained malicious code. Usually, the dropper that mimics an IPTV app opens a WebView with an IPTV website in it, while the actual malware is already installed and running on the device.”

The majority of Android malware campaigns using TV-related droppers have targeted Spain, Portugal, France, and Turkey over the past six months.

Massiv is the latest entrant to an already crowded Android threat landscape, reflecting the continuing demand for such turnkey solutions among cybercriminals.

“While not yet observed being promoted as Malware-as-a-Service, Massiv’s operator shows clear signs of going this path, introducing API keys to be used in malware communication with the backend,” ThreatFabric said. “Code analysis revealed ongoing development, with more features likely to be introduced in the future.”

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Twitter Email Print
Share
What do you think?
Love0
Sad0
Happy0
Sleepy0
Angry0
Dead0
Wink0
Previous Article Apple's March 4 Event Expected to Reveal New iPhone, iPads and MacBooks Apple's March 4 Event Expected to Reveal New iPhone, iPads and MacBooks
Next Article India AI Impact Summit begins | Computer Weekly India AI Impact Summit begins | Computer Weekly
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Stay Connected

248.1k Like
69.1k Follow
134k Pin
54.3k Follow

Latest News

Baidu CEO says robotaxi business ‘scale-up’ underway in 2025 · TechNode
Baidu CEO says robotaxi business ‘scale-up’ underway in 2025 · TechNode
Computing
This is the first time we’ve seen a fridge have a nugget ice machine built right in
This is the first time we’ve seen a fridge have a nugget ice machine built right in
Gadget
Agentic finance platform Stacks raises £17m – UKTN
Agentic finance platform Stacks raises £17m – UKTN
News
How 5G Technology Is Transforming Connectivity
How 5G Technology Is Transforming Connectivity
Gadget

You Might also Like

Baidu CEO says robotaxi business ‘scale-up’ underway in 2025 · TechNode
Computing

Baidu CEO says robotaxi business ‘scale-up’ underway in 2025 · TechNode

1 Min Read
Nairobi Exchange plans dedicated tech board to lure startups
Computing

Nairobi Exchange plans dedicated tech board to lure startups

5 Min Read
Reach vs. Impressions: How to Measure Campaign Success
Computing

Reach vs. Impressions: How to Measure Campaign Success

2 Min Read
How An AI Gmail Summary Agent Saves Me 35 Minutes a Day | HackerNoon
Computing

How An AI Gmail Summary Agent Saves Me 35 Minutes a Day | HackerNoon

18 Min Read
//

World of Software is your one-stop website for the latest tech news and updates, follow us now to get the news that matters to you.

Quick Link

  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact

Topics

  • Computing
  • Software
  • Press Release
  • Trending

Sign Up for Our Newsletter

Subscribe to our newsletter to get our newest articles instantly!

World of SoftwareWorld of Software
Follow US
Copyright © All Rights Reserved. World of Software.
Welcome Back!

Sign in to your account

Lost your password?