/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Check Point: Iranian hacker group Rampant Kitten, which has been active for 6+ years, has developed an Android malware capable of stealing 2FA SMS codes

the endpoint — then end-to-end encryption doesn't matter, the hacker now owns an end and can see content before anything is encrypted. The public doesn't really understand that and the NYT headline doesn't help. https://twitter.com/... Chris Vickery / @vickerysec : Called it. Called it so hard. https://twitter.com/... @iam_anandv : If you own the endpoint encryption is meaningless - This simple thing evades most of the folks working on the National Security Advisory Board in India. I call it as structural incompetence. https://twitter.com/... Chris Bing / @bing_chris : WhatsApp is encrypted end-to-end. If you're on device then it doesn't matter. As a result, a lot of the better spyware vendors have moved from bulk access platforms to tailored intrusion tools, which government clients prefer in order to siphon content from Signal, WhatsApp, etc. https://twitter.com/... Zuk / @ihackbanme : In the “surprising” news of anyone not following my feed: yes. Remote attacks on mobile are a thing, and they are widely more common than you think. Also, it's not just the Iranians, it's almost every other country that have 5-20+ very smart people, or a spare budget of $2-20m https://twitter.com/... Farnaz Fassihi / @farnazfassihi : Our exclusive story: A new group of Iranian Hackers & their vast cyber espionage operation targeting dissidents abroad & general public in Iran. They can infiltrate Telegram & download Whatsapp data w/ @ronenbergman https://www.nytimes.com/... @eff : Iranian hackers did not “beat” Telegram's encryption - they broke into a phone, which let them log in to the users' accounts. Strong end-to-end encryption is vital but doesn't eliminate the need for endpoint security https://www.nytimes.com/... Catalin Cimpanu / @campuscodi : NEW: Iranian hacker group developed Android malware to steal 2FA SMS codes -targeted Google 2FA SMS codes primarily -contained some vague functionality to do the same for Telegram and other social media apps https://www.zdnet.com/... https://twitter.com/...

ZDNet Catalin Cimpanu

Context & Ripple Effects

Check Point's report on Rampant Kitten slots into a five-year pattern of Android-side attacks on two-factor authentication rather than breaking crypto itself: earlier that same year researchers documented Cerberus, an Android banking trojan that extracts Google Authenticator one-time passwords, followed by work showing apps could grab the same codes via screenshots. The point analysts like Chris Vickery pressed in the surrounding discussion is that once an attacker owns the endpoint, end-to-end encryption protects nothing — the malware reads messages before they are ever encrypted.

First-order effects

  • Targets of Rampant Kitten's espionage who rely on SMS-based 2FA lose that factor entirely: the malware intercepts the codes on the device, so the attacker can authenticate as the victim even with strong encryption elsewhere in the stack.
  • Check Point's disclosure hands defenders and incident responders the indicators needed to hunt a group that had operated for six-plus years undetected.

Second-order effects

  • Every service still offering SMS as a second factor faces pressure to deprecate it, since the same interception technique works against any provider — the weakness is the channel, not any single company's implementation.
  • State-aligned groups watching this report gain a validated template: commodity-style Android stealer techniques, previously seen in criminal operations like the Telegram-bot-driven SMS stealer campaign Zimperium tracked across 113 countries, are portable into espionage toolkits at low cost.

Third-order effects

  • If endpoint compromise keeps defeating second factors, the industry's trust model shifts from 'what you receive' to device integrity itself — a trajectory later research like Pixnapping, which steals 2FA codes even after Google's partial September patch reinforced.
  • Authentication architecture migrates structurally toward hardware-bound and phishing-resistant factors, because software-delivered codes on compromised phones are now demonstrably a solved problem for attackers.

The trend: Two-factor authentication is being undermined not by broken cryptography but by Android endpoint compromise, as state and criminal groups alike industrialize one-time-code theft.

Discussion

  • @ericgeller Eric Geller on x
    Here are the relevant passages from the two reports. Again, note that this is all happening on the phone/computer, where the data is unencrypted. https://research.checkpoint.com/ ... https://miaan.org/... https://twitter.com/...
  • @dinodaizovi Dino A. Dai Zovi on x
    There is a real danger in interpreting this to conclude that E2EE is useless. E2EE breaks mass surveillance (now must be targeted) and abusing third-party doctrine to obtain any stored communications on a service provider. It's the difference between nuclear weapons and a sniper.…
  • @ericgeller Eric Geller on x
    Beware the misleading headline here. The Iranian hackers deployed malware that stole Telegram & WhatsApp data from devices. They didn't break encryption; they exfiltrated unencrypted data. If you can own the endpoint, encryption is meaningless. https://www.nytimes.com/...
  • @howelloneill Patrick Howell O'Neill on x
    If someone hacks your phone or computer — the endpoint — then end-to-end encryption doesn't matter, the hacker now owns an end and can see content before anything is encrypted. The public doesn't really understand that and the NYT headline doesn't help. https://twitter.com/...
  • @vickerysec Chris Vickery on x
    Called it. Called it so hard. https://twitter.com/...
  • @iam_anandv @iam_anandv on x
    If you own the endpoint encryption is meaningless - This simple thing evades most of the folks working on the National Security Advisory Board in India. I call it as structural incompetence. https://twitter.com/...
  • @bing_chris Chris Bing on x
    WhatsApp is encrypted end-to-end. If you're on device then it doesn't matter. As a result, a lot of the better spyware vendors have moved from bulk access platforms to tailored intrusion tools, which government clients prefer in order to siphon content from Signal, WhatsApp, etc.…
  • @ihackbanme Zuk on x
    In the “surprising” news of anyone not following my feed: yes. Remote attacks on mobile are a thing, and they are widely more common than you think. Also, it's not just the Iranians, it's almost every other country that have 5-20+ very smart people, or a spare budget of $2-20m ht…
  • @farnazfassihi Farnaz Fassihi on x
    Our exclusive story: A new group of Iranian Hackers & their vast cyber espionage operation targeting dissidents abroad & general public in Iran. They can infiltrate Telegram & download Whatsapp data w/ @ronenbergman https://www.nytimes.com/...
  • @eff @eff on x
    Iranian hackers did not “beat” Telegram's encryption - they broke into a phone, which let them log in to the users' accounts. Strong end-to-end encryption is vital but doesn't eliminate the need for endpoint security https://www.nytimes.com/...
  • @campuscodi Catalin Cimpanu on x
    NEW: Iranian hacker group developed Android malware to steal 2FA SMS codes -targeted Google 2FA SMS codes primarily -contained some vague functionality to do the same for Telegram and other social media apps https://www.zdnet.com/... https://twitter.com/...