/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Check Point: Iranian hacker group Rampant Kitten, which has been active for 6+ years, has developed an Android malware capable of stealing 2FA SMS codes

The malware could steal 2FA SMS codes for Google accounts.  Also contained vague functionality to do the same for Telegram and various social networks.

ZDNet Catalin Cimpanu

Context & Ripple Effects

Check Point's disclosure places Rampant Kitten inside a crowded 2020 wave of Android credential-theft tooling: months earlier, researchers had surfaced the Cerberus strain pulling one-time passwords straight out of Google Authenticator, and separately documented a screenshot-based method for stealing the same codes from Android apps, a flaw first disclosed back in 2014.

What distinguishes this entry is the actor and the vector — an Iranian group active for over six years going after SMS-delivered 2FA codes rather than authenticator-app tokens, with the description flagging Google accounts as the concrete target and Telegram plus social networks as vaguer ambitions.

First-order effects

  • Google account holders who rely on SMS-based two-factor authentication are directly exposed, since intercepted verification codes let an attacker pass the second factor without touching the password.
  • Telegram and various social networks sit in the malware's crosshairs at a 'vague functionality' level, meaning their users face a latent rather than confirmed risk until researchers pin down what the code actually does.

Second-order effects

  • Every disclosed SMS-stealing capability gives services another reason to steer users off text-message 2FA toward app-generated or hardware-backed factors, shifting authentication-burden decisions onto Google and every platform named in the malware's scope.
  • Detection vendors like Check Point convert these findings into product differentiation, while rival threat-intel teams are pushed to hunt for overlapping tooling among other long-active groups.

Third-order effects

  • The pattern across Cerberus, the screenshot technique, and later work like Pixnapping — which Google's September patch only partially mitigated — points to 2FA-code theft becoming a durable Android attack category that outlasts any single patch cycle.
  • At scale, the same SMS-interception playbook shows up in commodity crime too: [[a:871906|Zimperium tracked an SMS-stealer campaign reaching devices in 113 countries via Telegram bots]], suggesting state-linked and criminal operators are converging on the same weak channel — one that persists as long as SMS remains an accepted second factor.

The trend: Android 2FA attacks are converging on the SMS code itself — from authenticator-app token theft to SMS interception — steadily eroding text messages' viability as a second factor.

Discussion

  • @ericgeller Eric Geller on x
    Beware the misleading headline here. The Iranian hackers deployed malware that stole Telegram & WhatsApp data from devices. They didn't break encryption; they exfiltrated unencrypted data. If you can own the endpoint, encryption is meaningless. https://www.nytimes.com/...
  • @ericgeller Eric Geller on x
    Here are the relevant passages from the two reports. Again, note that this is all happening on the phone/computer, where the data is unencrypted. https://research.checkpoint.com/ ... https://miaan.org/... https://twitter.com/...
  • @campuscodi Catalin Cimpanu on x
    NEW: Iranian hacker group developed Android malware to steal 2FA SMS codes -targeted Google 2FA SMS codes primarily -contained some vague functionality to do the same for Telegram and other social media apps https://www.zdnet.com/... https://twitter.com/...
  • @howelloneill Patrick Howell O'Neill on x
    If someone hacks your phone or computer — the endpoint — then end-to-end encryption doesn't matter, the hacker now owns an end and can see content before anything is encrypted. The public doesn't really understand that and the NYT headline doesn't help. https://twitter.com/...
  • @ihackbanme Zuk on x
    In the “surprising” news of anyone not following my feed: yes. Remote attacks on mobile are a thing, and they are widely more common than you think. Also, it's not just the Iranians, it's almost every other country that have 5-20+ very smart people, or a spare budget of $2-20m ht…
  • @iam_anandv @iam_anandv on x
    If you own the endpoint encryption is meaningless - This simple thing evades most of the folks working on the National Security Advisory Board in India. I call it as structural incompetence. https://twitter.com/...
  • @farnazfassihi Farnaz Fassihi on x
    Our exclusive story: A new group of Iranian Hackers & their vast cyber espionage operation targeting dissidents abroad & general public in Iran. They can infiltrate Telegram & download Whatsapp data w/ @ronenbergman https://www.nytimes.com/...
  • @bing_chris Chris Bing on x
    WhatsApp is encrypted end-to-end. If you're on device then it doesn't matter. As a result, a lot of the better spyware vendors have moved from bulk access platforms to tailored intrusion tools, which government clients prefer in order to siphon content from Signal, WhatsApp, etc.…
  • @eff @eff on x
    Iranian hackers did not “beat” Telegram's encryption - they broke into a phone, which let them log in to the users' accounts. Strong end-to-end encryption is vital but doesn't eliminate the need for endpoint security https://www.nytimes.com/...