Frogblight is an Android banking trojan targeting users in Turkey. It has been distributed through SMS phishing campaigns and malicious Android applications masquerading as legitimate software, including a web browser and an application purportedly used to access court-related documents through a government service. Once installed, it attempts to steal banking credentials and device data from infected users. Reporting also indicates the malware is operated with a web-based control panel and is being developed in a malware-as-a-service model, suggesting an organized criminal ecosystem rather than a single isolated operator. Known references identify it primarily under the name Frogblight.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Frogblight is an Android malware targeting users in Turkey, stealing banking credentials and personal data, and is being developed for distribution as malware-as-a-service (MaaS).
Frogblight is an Android banking trojan targeting Turkish users, designed to steal banking credentials by masquerading as legitimate apps.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.