Alfa — Cyber Attacks, Breaches & Threat Activity

Threat entity extracted from intelligence sources

Frequency
1
occurrences
First Seen
November 12, 2025
Last Seen
November 12, 2025

Alfa is presented as a threat actor/organization tied to Android malware operations, notably the 'Fantasy Hub' Android RAT.

Overview

Alfa is presented as a threat actor/organization tied to Android malware operations, notably the 'Fantasy Hub' Android RAT. The group is described in relation to a Russian-backed campaign that exfiltrates financial data from infected Android devices, underscoring Alfa's focus on financial data theft on mobile platforms and its significance in the mobile threat landscape.

Related Threat Clusters

  • Russian 'Fantasy Hub' Android RAT Targets Financial Data Theft

    Zimperium and zLabs researchers have identified 'Fantasy Hub', a Russian malware-as-a-service Android RAT that enables attackers to control infected devices and steal sensitive information. The malware is marketed on…

    1 article · Updated November 12, 2025
  • Russian 'Fantasy Hub' Android RAT Targets Financial Data Theft

    Zimperium and zLabs researchers have identified 'Fantasy Hub', a Russian malware-as-a-service (MaaS) Android remote access trojan (RAT) that enables attackers to control infected devices and steal sensitive data. The…

    2 articles · Updated November 12, 2025

Recent Intelligence Reports

  • Russian 'Fantasy Hub' Android RAT exposes financial data — Scworld · November 12, 2025

CVSS v3.1 Breakdown