Skip to content
Russian 'Fantasy Hub' Android RAT Targets Financial Data Theft

Russian 'Fantasy Hub' Android RAT Targets Financial Data Theft

First seen 2 Dec 2025, 18:33 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •March 12, 2026 at 13:27 UTC

Zimperium and zLabs researchers have identified 'Fantasy Hub', a Russian malware-as-a-service (MaaS) Android remote access trojan (RAT) that enables attackers to control infected devices and steal sensitive data. The malware facilitates espionage through features like SMS interception, call log access, and fake banking windows aimed at credential theft, primarily targeting financial institutions.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 213d ago How this analysis works

More articles in this cluster (2)

Following this threat?

Track Fantasy Hub and Alfa in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed