Campaign Targeting Citizens of Uzbekistan via Fake Android Apps
ID: 56db8ba7-2a73-4fb7-8927-7ed88f144e5c
STIX ID: report--56db8ba7-2a73-4fb7-8927-7ed88f144e5c
Threat Score
75/100
Webamon researchers uncovered an ongoing campaign (first seen 2 Jul 2025, last observed 3 Dec 2025 with new domains as recently as 3 Mar 2026) involving 1,484 malicious domains impersonating Google Play pages; 120 of those domains hosted fake versions of 33 popular Uzbekistan apps (banking, government, telecom, social/entertainment). The fake pages targeted high-value services with millions of legitimate downloads, and while samples were not retrieved, the actors likely deploy infostealers and/or RATs to harvest credentials and access sensitive services.
