No recent events yet!
| Risk: | high | 
| Damage: | high | 
| Platform(s): | Android OS | 
| Advisory ID: | ngCERT-2025-050010 | 
| Version: | N/A | 
| CVE: | N/A | 
| Published: | May 28, 2025 | 
ngCERT’s attention has been drawn to a sophisticated android malware campaign tagged Tria Stealer. The trojan exploits android devices to harvest SMS data, as well as hijack WhatsApp and Telegram accounts. Reportedly, Tria Stealer is spread by luring unsuspecting persons into downloading a malicious Android Package Kit (APK), through fake wedding or event invitations sent on mobile messaging apps. Once installed, the trojan is capable of stealing sensitive data, and exploits the same for account hijacking as well as financial fraud. Consequently, android users and are advised to take proactive steps to safeguard their systems against Tria Stealer infiltration.
Tria Stealer malware spreads via fake wedding invitations on Telegram and WhatsApp, tricking users into downloading malicious APK files. Once installed, it masquerades as a system app and requests access to SMS, call logs, and app notifications. The malware then monitors and exfiltrates data from messages and emails to a C2 server on Telegram bots. It intercepts OTPs to hijack accounts and uses compromised accounts for scams and distribution of the malware.
Once activated, Tria Stealer employs sophisticated evasion techniques to avoid detection by security software and researchers. It uses encryption and obfuscation methods to conceal its activities and maintains persistence by reactivating itself every time the device is restarted. In addition to stealing sensitive information, the malware can also manipulate the infected device's settings and install additional payloads, further compromising the user's privacy and security.
To protect against Tria Stealer, users should be vigilant about the sources of their downloads and verify the authenticity of any unexpected invitations or links received through messaging platforms. Installing reputable antivirus software and regularly updating it can help detect and mitigate threats. Users should also enable two-factor authentication for their accounts and refrain from granting unnecessary permissions to apps, especially those not obtained from official app stores
Compromised of android systems by Tria Stealer malware could lead to the following:
The following are recommended:
1. Individuals should:
2. Organizations should:

