Android trojan linked to Cambodia following anomalous DNS spike

TL;DR AI
2 min readKey summary
Researchers traced a previously undocumented Android banking trojan to a Cambodia-linked malware operation near the K99 Triumph City compound.
The malware-as-a-service platform creates about 35 new domains a month and impersonates official and financial institutions in at least 21 countries.
Victims are tricked into installing fake apps that steal SMS verification codes, banking credentials, and facial-recognition data.
The campaign highlights how organized scam compounds can industrialize mobile fraud, account takeover, and cross-border money theft at scale.



