"Is that you in the video?": Creators of Mamont virus, which stole funds from bank cards, detained in Russia

The program was distributed via Telegram and disguised as applications and video files

сотрудники МВД задержали троих подозреваемых, которые создали и распространяли вредоносную программу «Мамонт», используемую для хищения средств с банковских карт. По данным ведомства, злоумышленники причастны к более чем 300 случаям кибермошенничества.

The program was distributed through Telegram channels, disguised as legitimate applications and video files. After infecting devices, the virus intercepted SMS messages from banks and allowed money to be transferred to controlled numbers and electronic wallets.

The detention operation was carried out by officers of the "K" department of the Ministry of Internal Affairs together with colleagues from the Saratov, Tula, and Ulyanovsk regions. Criminal cases have been initiated under Articles 159.6 ("Fraud in the field of computer information") and 272 of the Criminal Code of the Russian Federation ("Illegal access to computer information").

Previously, the Ministry of Internal Affairs reported that the virus uses apk files, often accompanied by questions like "Is that you in the video?" or containing the word "video" in the title.

Read more on the topic:

«Обновлённая» мошенническая схема «Мамонт» revealed in Russia

Mamont virus massively attacks Russians via Telegram: how not to fall for scammers' tricks

MIA: fraudsters create websites of non-existent cheap online stores and distribute the Mamont banking trojan