Check Point: Iranian hacker group Rampant Kitten, which has been active for 6+ years, has developed an Android malware capable of stealing 2FA SMS codes
the endpoint — then end-to-end encryption doesn't matter, the hacker now owns an end and can see content before anything is encrypted. The public doesn't really understand that and the NYT headline doesn't help. https://twitter.com/... Chris Vickery / @vickerysec : Called it. Called it so hard. https://twitter.com/... @iam_anandv : If you own the endpoint encryption is meaningless - This simple thing evades most of the folks working on the National Security Advisory Board in India. I call it as structural incompetence. https://twitter.com/... Chris Bing / @bing_chris : WhatsApp is encrypted end-to-end. If you're on device then it doesn't matter. As a result, a lot of the better spyware vendors have moved from bulk access platforms to tailored intrusion tools, which government clients prefer in order to siphon content from Signal, WhatsApp, etc. https://twitter.com/... Zuk / @ihackbanme : In the “surprising” news of anyone not following my feed: yes. Remote attacks on mobile are a thing, and they are widely more common than you think. Also, it's not just the Iranians, it's almost every other country that have 5-20+ very smart people, or a spare budget of $2-20m https://twitter.com/... Farnaz Fassihi / @farnazfassihi : Our exclusive story: A new group of Iranian Hackers & their vast cyber espionage operation targeting dissidents abroad & general public in Iran. They can infiltrate Telegram & download Whatsapp data w/ @ronenbergman https://www.nytimes.com/... @eff : Iranian hackers did not “beat” Telegram's encryption - they broke into a phone, which let them log in to the users' accounts. Strong end-to-end encryption is vital but doesn't eliminate the need for endpoint security https://www.nytimes.com/... Catalin Cimpanu / @campuscodi : NEW: Iranian hacker group developed Android malware to steal 2FA SMS codes -targeted Google 2FA SMS codes primarily -contained some vague functionality to do the same for Telegram and other social media apps https://www.zdnet.com/... https://twitter.com/...
Context & Ripple Effects
Check Point's report on Rampant Kitten slots into a five-year pattern of Android-side attacks on two-factor authentication rather than breaking crypto itself: earlier that same year researchers documented Cerberus, an Android banking trojan that extracts Google Authenticator one-time passwords, followed by work showing apps could grab the same codes via screenshots. The point analysts like Chris Vickery pressed in the surrounding discussion is that once an attacker owns the endpoint, end-to-end encryption protects nothing — the malware reads messages before they are ever encrypted.
First-order effects
- Targets of Rampant Kitten's espionage who rely on SMS-based 2FA lose that factor entirely: the malware intercepts the codes on the device, so the attacker can authenticate as the victim even with strong encryption elsewhere in the stack.
- Check Point's disclosure hands defenders and incident responders the indicators needed to hunt a group that had operated for six-plus years undetected.
Second-order effects
- Every service still offering SMS as a second factor faces pressure to deprecate it, since the same interception technique works against any provider — the weakness is the channel, not any single company's implementation.
- State-aligned groups watching this report gain a validated template: commodity-style Android stealer techniques, previously seen in criminal operations like the Telegram-bot-driven SMS stealer campaign Zimperium tracked across 113 countries, are portable into espionage toolkits at low cost.
Third-order effects
- If endpoint compromise keeps defeating second factors, the industry's trust model shifts from 'what you receive' to device integrity itself — a trajectory later research like Pixnapping, which steals 2FA codes even after Google's partial September patch reinforced.
- Authentication architecture migrates structurally toward hardware-bound and phishing-resistant factors, because software-delivered codes on compromised phones are now demonstrably a solved problem for attackers.
The trend: Two-factor authentication is being undermined not by broken cryptography but by Android endpoint compromise, as state and criminal groups alike industrialize one-time-code theft.