Riltok

MITRE ATT&CK: S0403 View on attack.mitre.org

Aliases: Riltok

Malware type
trojan, credential-stealer
Family
Malware family
Operating systems
android
Related IoCs
1 (1 malicious)
Last IoC activity
2026-07-20 00:19:07
Profile updated
2026-07-07 13:45:15

Targeted industries: financial-services

Targeted regions: country_code:ru country_code:fr country_code:it

Context

Riltok is banking malware that uses phishing popups to collect user credentials.

Recent IoC activity

1 malicious indicator in Maltiverse are attributed to Riltok (S0403). The 1 most recently updated:

TypeIndicatorUpdatedSources
file sample 0497b6000a7a23e9e9b97472bc2d3799caf49cbbea1627ad4d87ae6e0b7e2a98.apk 2026-07-20 1

Malware & tools used

  • System Network Configuration Discovery (attack-pattern)
  • Web Protocols (attack-pattern)
  • Contact List (attack-pattern)
  • Software Discovery (attack-pattern)
  • System Information Discovery (attack-pattern)
  • GUI Input Capture (attack-pattern)
  • SMS Messages (attack-pattern)
  • Input Injection (attack-pattern)

Reports & references

  • medium.com — Inside View Of Brazzzersff Infrastructure 89B9188Fd145 (report)
  • malpedia.caad.fkie.fraunhofer.de — Apk.Riltok (report)
  • Kaspersky — 91374 (report)
  • MITRE ATT&CK — S0403 (report)

External references