Check Point: Iranian hacker group Rampant Kitten, which has been active for 6+ years, has developed an Android malware capable of stealing 2FA SMS codes
The malware could steal 2FA SMS codes for Google accounts. Also contained vague functionality to do the same for Telegram and various social networks.
What distinguishes this entry is the actor and the vector — an Iranian group active for over six years going after SMS-delivered 2FA codes rather than authenticator-app tokens, with the description flagging Google accounts as the concrete target and Telegram plus social networks as vaguer ambitions.
First-order effects
Google account holders who rely on SMS-based two-factor authentication are directly exposed, since intercepted verification codes let an attacker pass the second factor without touching the password.
Telegram and various social networks sit in the malware's crosshairs at a 'vague functionality' level, meaning their users face a latent rather than confirmed risk until researchers pin down what the code actually does.
Second-order effects
Every disclosed SMS-stealing capability gives services another reason to steer users off text-message 2FA toward app-generated or hardware-backed factors, shifting authentication-burden decisions onto Google and every platform named in the malware's scope.
Detection vendors like Check Point convert these findings into product differentiation, while rival threat-intel teams are pushed to hunt for overlapping tooling among other long-active groups.
At scale, the same SMS-interception playbook shows up in commodity crime too: [[a:871906|Zimperium tracked an SMS-stealer campaign reaching devices in 113 countries via Telegram bots]], suggesting state-linked and criminal operators are converging on the same weak channel — one that persists as long as SMS remains an accepted second factor.
The trend: Android 2FA attacks are converging on the SMS code itself — from authenticator-app token theft to SMS interception — steadily eroding text messages' viability as a second factor.
Beware the misleading headline here. The Iranian hackers deployed malware that stole Telegram & WhatsApp data from devices. They didn't break encryption; they exfiltrated unencrypted data. If you can own the endpoint, encryption is meaningless. https://www.nytimes.com/...
Here are the relevant passages from the two reports. Again, note that this is all happening on the phone/computer, where the data is unencrypted. https://research.checkpoint.com/ ... https://miaan.org/... https://twitter.com/...
NEW: Iranian hacker group developed Android malware to steal 2FA SMS codes -targeted Google 2FA SMS codes primarily -contained some vague functionality to do the same for Telegram and other social media apps https://www.zdnet.com/... https://twitter.com/...
If someone hacks your phone or computer — the endpoint — then end-to-end encryption doesn't matter, the hacker now owns an end and can see content before anything is encrypted. The public doesn't really understand that and the NYT headline doesn't help. https://twitter.com/...
In the “surprising” news of anyone not following my feed: yes. Remote attacks on mobile are a thing, and they are widely more common than you think. Also, it's not just the Iranians, it's almost every other country that have 5-20+ very smart people, or a spare budget of $2-20m ht…
If you own the endpoint encryption is meaningless - This simple thing evades most of the folks working on the National Security Advisory Board in India. I call it as structural incompetence. https://twitter.com/...
Our exclusive story: A new group of Iranian Hackers & their vast cyber espionage operation targeting dissidents abroad & general public in Iran. They can infiltrate Telegram & download Whatsapp data w/ @ronenbergman https://www.nytimes.com/...
WhatsApp is encrypted end-to-end. If you're on device then it doesn't matter. As a result, a lot of the better spyware vendors have moved from bulk access platforms to tailored intrusion tools, which government clients prefer in order to siphon content from Signal, WhatsApp, etc.…
Iranian hackers did not “beat” Telegram's encryption - they broke into a phone, which let them log in to the users' accounts. Strong end-to-end encryption is vital but doesn't eliminate the need for endpoint security https://www.nytimes.com/...